Impact
Memory safety bugs were discovered in Mozilla Firefox 139 and Thunderbird 139. The defects involve unsafe memory handling that could corrupt the application’s memory space, potentially allowing an attacker to execute arbitrary code. These vulnerabilities are classified as CWE‑119, indicating out‑of‑bounds or invalid memory accesses.
Affected Systems
Mozilla Firefox version 139 and Mozilla Thunderbird version 139 are affected. Any installation of these releases on any platform remains vulnerable until the fix in version 140 is applied.
Risk and Exploitability
The CVSS score of 8.1 signals high severity. The EPSS score, calculated from the provided value of 0.02878, is approximately 2.88%, indicating a modest likelihood of exploitation. The advisory notes that the issue is not listed in CISA’s KEV catalog, suggesting no known widespread exploitation to date. Treated as inferred, the likely attack vector would involve an attacker delivering malicious web content or email that triggers the vulnerable memory handling within the application, but additional effort would be required to construct a working exploit.
OpenCVE Enrichment
EUVD
Ubuntu USN