Impact
These memory safety bugs were discovered in Firefox 134 and Thunderbird 134 and involve buffer copy or out‑of‑bounds write vulnerabilities that can corrupt memory. In theory, with sufficient effort an attacker could exploit the corruption to execute arbitrary code on the victim’s system. The weakness is reflected in CWE‑120 and CWE‑787, indicating unsafe handling of memory boundaries.
Affected Systems
Mozilla Firefox 134 and Mozilla Thunderbird 134 are affected. The fixes were released in Firefox 135 and Thunderbird 135 respectively.
Risk and Exploitability
The CVSS score of 9.8 points to a severe risk, but the EPSS score of < 1% suggests that exploitation is unlikely at present. The vulnerability is not listed in the CISA KEV catalog, indicating no confirmed widespread attacks. Nevertheless, the potential for remote code execution makes this a critical upgrade target, especially in environments where vulnerable versions may remain installed.
OpenCVE Enrichment
EUVD
Ubuntu USN