CVE-2026-5732

HIGH

Incorrect boundary conditions, integer overflow in the Graphics: Text component

Title source: cna
STIX 2.1

Description

Incorrect boundary conditions, integer overflow in the Graphics: Text component. This vulnerability was fixed in Firefox 149.0.2, Firefox ESR 140.9.1, Thunderbird 149.0.2, and Thunderbird 140.9.1.

Scores

CVSS v3 8.8
EPSS 0.0004
EPSS Percentile 12.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-190
Status published
Products (10)
mozilla/firefox < 140.9.1
mozilla/firefox < 149.0.2
Mozilla/Firefox 140.9.1 - 140.*
Mozilla/Firefox 149.0.2
Mozilla/Firefox unspecified - 149.0.2
Mozilla/Firefox ESR unspecified - 140.9.1
Mozilla/Thunderbird 140.9.1 - 140.*
Mozilla/Thunderbird 149.0.2
Mozilla/Thunderbird unspecified - 140.9.1
Mozilla/Thunderbird unspecified - 149.0.2
Published Apr 07, 2026
Tracked Since Apr 07, 2026