Integer overflow in the WebGL subsystem in Mozilla Firefox before 17.0, Firefox ESR 10.x before 10.0.11, Thunderbird before 17.0, Thunderbird ESR 10.x before 10.0.11, and SeaMonkey before 2.14 allows remote attackers to execute arbitrary code or cause a denial of service (invalid write operation) via crafted data.
CVSS Vector
AV:N/AC:L/Au:N/C:C/I:C/A:CCanonical Ubuntu
OSCanonical10.0411.1012.0412.10Mozilla Firefox
APPMozilla< 10.0.11< 17.0Mozilla Seamonkey
APPMozilla< 2.14Mozilla Thunderbird
APPMozilla< 17.0Mozilla Thunderbird Esr
APPMozilla< 10.0.11Opensuse
OSOpensuse11.412.112.2Red Hat Enterprise Linux Desktop
OSRedhat5.06.0Red Hat Enterprise Linux Eus
OSRedhat6.3Red Hat Enterprise Linux Server
OSRedhat5.06.0Red Hat Enterprise Linux Workstation
OSRedhat5.06.0SUSE Linux Enterprise Desktop
OSSuse1011SUSE Linux Enterprise Server
OSSuse1011SUSE Linux Enterprise Software Development Kit
OSSuse1011
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
RCEDoS
CWE
References
Related vulnerabilities
CVE-2025-32463CRITICAL9.3⚠ KEVPL ✓same product
Sudo: eskalacja uprawnień do root poprzez opcję --chroot (CVE-2025-32463)
CVE-2024-9680CRITICAL9.8⚠ KEVPL ✓same product
Use-after-free w Animation timelines Firefox/Thunderbird — RCE
CVE-2022-26486CRITICAL9.6⚠ KEVPL ✓same product
Use-after-free w WebGPU IPC framework Mozilla — sandbox escape
CVE-2022-0543CRITICAL10.0⚠ KEVPL ✓same product
Redis – ucieczka z Lua sandbox umożliwiająca zdalne wykonanie kodu (RCE)
CVE-2021-40438CRITICAL9.0⚠ KEVPL ✓same product
SSRF w mod_proxy Apache HTTP Server — przekierowanie żądań przez atakującego