logo

Multiple Vulnerabilities in Mozilla Products Could Allow for Arbitrary Code Execution

ID: 076d6ac7-6a52-5745-951a-e979ab9e81f4

STIX ID: report--076d6ac7-6a52-5745-951a-e979ab9e81f4

Feed Name: CISecurity.org Advisories

Threat Score
75/100

Date Published: 2025-12-09

Date Updated: 2026-04-27

...
...

Multiple high-severity vulnerabilities have been disclosed in Mozilla products (Firefox, Thunderbird, and ESR) covering use-after-free, sandbox escape, privilege escalation, JIT miscompilation, and memory-safety issues across several CVEs (CVE-2025-14321 through CVE-2025-14333). The most serious flaws could allow arbitrary code execution, enabling attackers to install programs, access or modify data, or create accounts with full privileges; fixes are included in Firefox 146 and Thunderbird 146 (and ESR 140.6) and administrators should apply updates promptly.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.