CVE-2025-10532

Description

Incorrect boundary conditions in the JavaScript: GC component. This vulnerability was fixed in Firefox 143, Firefox ESR 140.3, Thunderbird 143, and Thunderbird 140.3.

Risk Information

Base Score
6.5
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
EPSS Score
Exploitation Probability
0.065

Associated Vulnerability

VulnerabilityOS Platform
Multiple vulnerabilities are fixed in Mozilla Firefox ESR (140) (140.3.0)Windows
Multiple vulnerabilities are fixed in Mozilla Firefox ESR (140) (x64) (140.3.0)Windows
Multiple vulnerabilities are fixed in Mozilla Firefox (143.0)Windows
Multiple vulnerabilities are fixed in Mozilla Firefox (x64) (143.0)Windows
Multiple vulnerabilities are fixed in Mozilla Thunderbird (143.0)Windows
Multiple vulnerabilities are fixed in Mozilla Thunderbird (x64) (143.0)Windows
Multiple vulnerabilities are fixed in Mozilla Thunderbird ESR 140 (140.3.0)Windows
Multiple vulnerabilities are fixed in Mozilla Thunderbird ESR 140 (x64) (140.3.0)Windows
Vulnerabilities CVE-2025-10527,CVE-2025-10528,CVE-2025-10532,CVE-2025-10533 are affected in Mozilla Thunderbird 140.2.9Windows
Multiple Vulnerabilities are affected in Mozilla Thunderbird 142.9Windows
Multiple Vulnerabilities are affected in Mozilla Thunderbird 140.2.9Windows
Multiple Vulnerabilities are affected in Mozilla Firefox (x64) 140.2.99Windows
Multiple Vulnerabilities are affected in Mozilla_Firefox 140.2.99Windows
Multiple Vulnerabilities are affected in Mozilla Firefox (x64) 142.99Windows
Multiple Vulnerabilities are affected in Mozilla_Firefox 142.99Windows
Multiple vulnerabilities are fixed in Mozilla Firefox For Mac (143.0)Mac
Multiple vulnerabilities are fixed in Mozilla Firefox For Mac (143.0.1)Mac
Multiple vulnerabilities are fixed in Mozilla Firefox For Mac (143.0.3)Mac
Multiple vulnerabilities are fixed in Mozilla Firefox For Mac (143.0.4)Mac

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-351570Mozilla Firefox ESR (140) (140.3.0)
PATCH-351571Mozilla Firefox ESR (140) (x64) (140.3.0)
PATCH-351568Mozilla Firefox (143.0)
PATCH-351569Mozilla Firefox (x64) (143.0)
PATCH-351572Mozilla Thunderbird (143.0)
PATCH-351573Mozilla Thunderbird (x64) (143.0)
PATCH-351641Mozilla Thunderbird ESR 140 (140.3.0)
PATCH-351642Mozilla Thunderbird ESR 140 (x64) (140.3.0)
PATCH-613630Mozilla Firefox For Mac (147.0.4)
PATCH-613630Mozilla Firefox For Mac (147.0.4)
PATCH-613630Mozilla Firefox For Mac (147.0.4)
PATCH-613630Mozilla Firefox For Mac (147.0.4)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234