Junglewise Threat Intelligence

CVE-2026-4694: Mozilla Firefox and Thunderbird integer overflow in Graphics component

CVE-2026-4694 · Severity: high · CVSS 7.5 · Published 2026-03-24

Technologies: Mozilla Thunderbird, Mozilla Firefox ESR, Mozilla Firefox. Vendors: Red Hat, Mozilla.

Executive brief

A vulnerability exists in the graphics processing component of Mozilla Firefox and Thunderbird. This flaw could allow an attacker to cause the application to crash or become unresponsive by processing specially crafted visual content. This primarily impacts the availability of the browser or email client, potentially disrupting user operations.

Technical details

An integer overflow vulnerability (CWE-190) exists in the Graphics component of Mozilla Firefox and Thunderbird due to incorrect boundary conditions (CWE-754). The flaw can be triggered remotely without authentication if the application processes malicious graphical content. According to the CVSS vector, the primary impact is on system availability (Denial of Service), though memory corruption bugs in these components often carry a risk of arbitrary code execution. Patches are available in Firefox 149, Firefox ESR 115.34, Firefox ESR 140.9, and Thunderbird versions 149 and 140.9.

Affected products

  • Mozilla Firefox < 149
  • Mozilla Firefox ESR < 115.34, < 140.9
  • Mozilla Thunderbird < 149, < 140.9
  • Red Hat Enterprise Linux Server (v. 7 ELS) 7

Timeline

  • 2026-03-24: disclosed
  • 2026-03-24: advisory
  • 2026-03-24: patched

References

Related threats