CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2026-5734

Critical · CVSS 9.8

Mozilla Firefox / Thunderbird — Memory safety bugs / buffer overflow / out-of-bounds write leading to arbitrary code execution

CVSS
9.8
nvd
EPSS
KEV
No
Class
other
CWE-787, CWE-120, CWE-787

Description

Memory safety bugs present in Firefox ESR 140.9.0, Thunderbird ESR 140.9.0, Firefox 149.0.1 and Thunderbird 149.0.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 149.0.2, Firefox ESR 140.9.1, Thunderbird 149.0.2, and Thunderbird 140.9.1.

Search profile — drives PoC discovery

Symbols bug_id=2022369bug_id=2023026bug_id=2023545bug_id=2023555bug_id=2023958bug_id=2025422bug_id=2025468bug_id=2025492bug_id=2025505mfsa2026-25mfsa2026-27mfsa2026-28mfsa2026-29
Keywords CVE-2026-5734Firefox memory safetyThunderbird memory corruptionFirefox 149.0.1 exploitFirefox ESR 140.9.0 exploitmfsa2026-25mfsa2026-27mfsa2026-28mfsa2026-29CWE-787 FirefoxCWE-120 FirefoxFirefox arbitrary code execution 2026Firefox buffer overflow PoC
Versions: Firefox < 149.0.2, Firefox ESR < 140.9.1, Thunderbird < 149.0.2, Thunderbird ESR < 140.9.1

References

Status: enriched · ingested 2026-06-30T06:00:22.000Z · profiled 2026-07-01T18:30:14.000Z