Mozilla has released security updates for its Firefox browser and Thunderbird mail clientto fix vulnerabilitiesthat could put users at risk.

The company patched 13 vulnerabilities in the Firefox browser with the release of Firefox 95.Six of these vulnerabilities have been rated as very serious.
See also: Researchers found 226 vulnerabilities in nine popular WiFi routers
The most dangerous of these bugs could allow an attacker to execute code, which could potentially lead to a complete system compromise.
Firefox also fixed a URL leakage bug, known as CVE-2021-43536.
Another vulnerability that Mozilla is fixing with the new security updates is CVE-2021-43539 (GC rooting failure). The company has also fixed important security issues affecting Firefox, Firefox ESR, and Thunderbird.
See also: Mozilla ends support for Firefox Lockwise app
Finally, the updates address memory bugs in Firefox 95 and Firefox ESR 91.4 that could lead to malicious code execution.

"Some of these errors showed evidence of memory corruption and we assume that with enough effort some of them could be used to execute malicious code," the advisory states.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) also issued an alert urging organizations to apply Mozilla security updates to protect themselves from the vulnerabilities.
See also: SonicWall: Fixed critical SMA 100 bugs - Update your systems immediately
“ Mozilla has released security updates to address vulnerabilities in Firefox, Firefox ESR, and Thunderbird. An attacker could exploit some of these vulnerabilities to take control of an affected system. CISA encourages users and administrators to review Mozilla’s security advisories for Firefox 95, Firefox ESR 91.4.0, and Thunderbird 91.4.0 and apply the necessary updates ,” CISA said
More details about the vulnerabilities can be found here.
Source: securityaffairs.co
