Igor Morgenstern

#3569of 53,633
72.4Total CVSS
Vulnerabilities · 9
Medium
2
High
5
Critical
2
PT-2025-46356
10
2025-11-11
Mozilla · Firefox Esr · CVE-2025-13016
**Name of the Vulnerable Software and Affected Versions** Mozilla Firefox versions prior to 145 Mozilla Firefox ESR versions prior to 140.5 Thunderbird versions prior to 145 Thunderbird versions prior to 140.5 Mozilla Firefox ESR versions prior to 140.5.0esr-1~deb11u1 Mozilla Firefox ESR versions prior to 140.5.0esr-1~deb12u1 Mozilla Firefox ESR versions prior to 140.5.0esr-1~deb13u1 Thunderbird versions prior to 1:140.5.0esr-1~deb12u1 Thunderbird versions prior to 1:140.5.0esr-1~deb13u1 Thunderbird versions prior to 1:140.5.0esr-1~deb11u1 **Description** A flaw exists in the JavaScript WebAssembly component of Firefox and Thunderbird due to incorrect boundary conditions, leading to a stack buffer overflow. This vulnerability could allow a remote attacker to execute arbitrary code via a malicious webpage. Approximately 180 million users may be affected. The issue is related to the WebAssembly garbage collection and involves faulty pointer math. Exploitation could lead to arbitrary code execution, session hijacking, or full system compromise. **Recommendations** Upgrade Firefox to version 145 or later. Upgrade Firefox ESR to version 140.5 or later. Upgrade Thunderbird to version 145 or later. Upgrade Thunderbird to version 140.5 or later. Upgrade Firefox ESR to version 140.5.0esr-1~deb11u1 or later. Upgrade Firefox ESR to version 140.5.0esr-1~deb12u1 or later. Upgrade Firefox ESR to version 140.5.0esr-1~deb13u1 or later. Upgrade Thunderbird to version 1:140.5.0esr-1~deb12u1 or later. Upgrade Thunderbird to version 1:140.5.0esr-1~deb13u1 or later. Upgrade Thunderbird to version 1:140.5.0esr-1~deb11u1 or later.