Impact
The vulnerability stems from memory safety bugs that can lead to buffer overflows and memory corruption. If successfully exploited, an attacker may execute arbitrary code, compromising system integrity. The issue is identified as CWE-119.
Affected Systems
Mozilla Firefox versions 140.0 and 141, including the ESR 140.0 and ESR 140.1 releases, are affected. Mozilla Thunderbird versions 140.0 and 141, including the ESR 140.0 and ESR 140.1 releases, are also impacted. Only these specific build numbers are noted as vulnerable in the official advisories.
Risk and Exploitability
The CVSS score of 8.8 indicates high severity, while the EPSS score of less than 1% suggests low current exploitation probability. This CVE is not listed in the CISA KEV catalog. The description implies that exploiting these bugs would require considerable effort, potentially involving crafted web pages or email attachments. The likely attack vector, inferred from common memory corruption exploitation patterns, would be remote through malicious content processed by the client applications.
OpenCVE Enrichment
EUVD
Ubuntu USN