Incorrect boundary conditions, integer overflow in the Graphics: Text component. This vulnerability was fixed in Firefox 149.0.2, Firefox ESR 140.9.1, Thunderbird 149.0.2, and Thunderbird 140.9.1.
https://www.mozilla.org/security/advisories/mfsa2026-29/
https://www.mozilla.org/security/advisories/mfsa2026-28/
https://www.mozilla.org/security/advisories/mfsa2026-27/