PT-2025-46356 · Mozilla+8 · Firefox Esr+9

Aisle Research

+1

·

Published

2025-11-11

·

Updated

2026-02-11

·

CVE-2025-13016

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Mozilla Firefox versions prior to 145 Mozilla Firefox ESR versions prior to 140.5 Thunderbird versions prior to 145 Thunderbird versions prior to 140.5 Mozilla Firefox ESR versions prior to 140.5.0esr-1deb11u1 Mozilla Firefox ESR versions prior to 140.5.0esr-1deb12u1 Mozilla Firefox ESR versions prior to 140.5.0esr-1deb13u1 Thunderbird versions prior to 1:140.5.0esr-1deb12u1 Thunderbird versions prior to 1:140.5.0esr-1deb13u1 Thunderbird versions prior to 1:140.5.0esr-1deb11u1
Description A flaw exists in the JavaScript WebAssembly component of Firefox and Thunderbird due to incorrect boundary conditions, leading to a stack buffer overflow. This vulnerability could allow a remote attacker to execute arbitrary code via a malicious webpage. Approximately 180 million users may be affected. The issue is related to the WebAssembly garbage collection and involves faulty pointer math. Exploitation could lead to arbitrary code execution, session hijacking, or full system compromise.
Recommendations Upgrade Firefox to version 145 or later. Upgrade Firefox ESR to version 140.5 or later. Upgrade Thunderbird to version 145 or later. Upgrade Thunderbird to version 140.5 or later. Upgrade Firefox ESR to version 140.5.0esr-1deb11u1 or later. Upgrade Firefox ESR to version 140.5.0esr-1deb12u1 or later. Upgrade Firefox ESR to version 140.5.0esr-1deb13u1 or later. Upgrade Thunderbird to version 1:140.5.0esr-1deb12u1 or later. Upgrade Thunderbird to version 1:140.5.0esr-1deb13u1 or later. Upgrade Thunderbird to version 1:140.5.0esr-1deb11u1 or later.

Fix

RCE

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2025:21280
ALSA-2025:21281
ALSA-2025:21843
ALSA-2025:21881
ALSA-2025:22363
ALT-PU-2025-14358
ALT-PU-2025-14554
ALT-PU-2025-14878
BDU:2025-14548
CESA-2025_21881
CESA-2025_22363
CVE-2025-13016
DLA-4370-1
DLA-4372-1
DSA-6054-1
DSA-6059-1
INFSA-2025_21280
INFSA-2025_21842
INFSA-2025_21881
INFSA-2025_22363
MGASA-2025-0300
MGASA-2025-0305
OESA-2025-2770
OPENSUSE-SU-2025:15735-1
OPENSUSE-SU-2025:15738-1
OPENSUSE-SU-2025:20065-1
OPENSUSE-SU-2026:20002-1
RHSA-2025_21280
RHSA-2025_21842
RHSA-2025_21881
SUSE-SU-2025:21021-1
SUSE-SU-2025:4173-1
SUSE-SU-2025:4174-1
SUSE-SU-2025:4195-1
USN-7991-1

Affected Products

Alt Linux
Almalinux
Centos
Firefox
Firefox Esr
Linuxmint
Red Hat
Rocky Linux
Suse
Ubuntu