cbcvebase.
CVE-2025-10533
published 2025-09-16

CVE-2025-10533: Integer overflow in the SVG component. This vulnerability was fixed in Firefox 143, Firefox ESR 115.28, Firefox ESR 140.3, Thunderbird 143, and Thunderbird…

high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
Integer overflow in the SVG component. This vulnerability was fixed in Firefox 143, Firefox ESR 115.28, Firefox ESR 140.3, Thunderbird 143, and Thunderbird 140.3.

Affected

13 ranges
VendorProductVersion rangeFixed in
debianfirefox< firefox 143.0-1 (sid)firefox 143.0-1 (sid)
debianfirefox-esr< firefox 143.0-1 (sid)firefox 143.0-1 (sid)
debianthunderbird< firefox 143.0-1 (sid)firefox 143.0-1 (sid)
mozillafirefox< 115.28.0115.28.0
mozillafirefox< 143.0143.0
mozillafirefox
mozillafirefox>= 116.0 < 140.3140.3
mozillathunderbird< 140.3.0140.3.0
mozillathunderbird>= 0 < 1:140.3.0esr-1~deb11u11:140.3.0esr-1~deb11u1
mozillathunderbird>= 0 < 1:140.3.0esr-1~deb12u11:140.3.0esr-1~deb12u1
mozillathunderbird>= 0 < 1:140.3.0esr-1~deb13u11:140.3.0esr-1~deb13u1
mozillathunderbird>= 0 < 1:140.3.0esr-11:140.3.0esr-1
mozillathunderbird>= 141.0 < 143.0143.0

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv8.8HIGH