Impact
The vulnerability is a memory safety bug affecting Firefox 140 and Thunderbird 140. Multiple bugs led to memory corruption; the description states that with sufficient effort, some could have been exploited to execute arbitrary code. The core weakness is classified as CWE‑119, a buffer overread or overwrite. This flaw threatens confidentiality, integrity, and availability by enabling an attacker to take control of the affected applications and potentially the underlying system.
Affected Systems
The affected products are Mozilla’s Firefox browser and Thunderbird email client. The bugs exist in release 140 of each product and were addressed in Firefox 141 and Thunderbird 141.
Risk and Exploitability
The CVSS score of 9.8 indicates a critical severity. However, the EPSS score is reported as < 1 %, suggesting exploitation probability is very low at present, and the flaw is not yet catalogued in the CISA KEV. The likely attack vector, though not explicitly stated, is inferred to be based on memory corruption via input received by the application (such as crafted files or network traffic). Successful exploitation would allow an attacker to execute code with the privileges of the user running the application.
OpenCVE Enrichment
EUVD