CVE-2026-5732

HIGH

Incorrect boundary conditions, integer overflow in the Graphics: Text component

Title source: cna
STIX 2.1

Description

Incorrect boundary conditions, integer overflow in the Graphics: Text component. This vulnerability was fixed in Firefox 149.0.2, Firefox ESR 140.9.1, Thunderbird 149.0.2, and Thunderbird 140.9.1.

References (32)

Core 32
Core References

Scores

CVSS v3 8.8
EPSS 0.0035
EPSS Percentile 27.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-190
Status published
Products (10)
mozilla/firefox < 140.9.1
mozilla/firefox < 149.0.2
Mozilla/Firefox 140.9.1 - 140.*
Mozilla/Firefox 149.0.2
Mozilla/Firefox unspecified - 149.0.2
Mozilla/Firefox ESR unspecified - 140.9.1
Mozilla/Thunderbird 140.9.1 - 140.*
Mozilla/Thunderbird 149.0.2
Mozilla/Thunderbird unspecified - 140.9.1
Mozilla/Thunderbird unspecified - 149.0.2
Published Apr 07, 2026
Tracked Since Apr 07, 2026