Impact
This CVE describes memory safety bugs in Firefox 138 and Thunderbird 138 that can corrupt memory. The vendor notes that some bugs provided evidence of memory corruption and the possibility of arbitrary code execution with enough effort. The weaknesses correspond to buffer overflows (CWE-119) and out‑of‑bounds writes (CWE-787).
Affected Systems
Mozilla Firefox 138 and Mozilla Thunderbird 138 are affected. All installations of these products that have not been updated to version 139 or newer remain vulnerable. The vulnerability is specific to the Firefox and Thunderbird codebases.
Risk and Exploitability
The CVSS score is 7.3, indicating substantial severity. The EPSS score is below 1 %, suggesting that at the time of analysis the likelihood of exploitation was considered low. The vulnerability is not listed in the CISA KEV catalog. Exploitation would require an attacker to deliver crafted content to the application, such as a malicious web page or email, to trigger the memory corruption, which could in turn allow arbitrary code execution. No specific prerequisites beyond the vulnerable client are noted, so the attack could target any user of the affected versions.
OpenCVE Enrichment
EUVD
Ubuntu USN