logo

Multiple Vulnerabilities in Mozilla Products Could Allow for Arbitrary Code Execution

ID: 01136b9c-f1ea-5a7a-b44b-3d9467608c41

STIX ID: report--01136b9c-f1ea-5a7a-b44b-3d9467608c41

Feed Name: CISecurity.org Advisories

Threat Score
70/100

Date Published: 2025-03-12

Date Updated: 2026-04-27

...
...

Multiple critical and lower-severity vulnerabilities were disclosed in Mozilla products (Firefox, Thunderbird, and ESR), including memory-safety and use-after-free bugs (e.g., CVE-2024-43097, CVE-2025-1930–1933, 1937, 1938, 1943) that could allow arbitrary code execution, plus other issues such as tapjacking, clickjacking, and passkey phishing; affected versions include Firefox 136, Thunderbird 136, and various ESR releases. Successful exploitation of the most severe flaws could let attackers install programs, view/change/delete data, or create accounts with elevated privileges, though the report does not indicate active exploitation in the wild.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.