Impact
Memory safety bugs in older versions of Mozilla Firefox and Thunderbird caused memory corruption, potentially enabling an attacker to execute arbitrary code. The vulnerabilities are identified as buffer overrun (CWE-119) and carry a CVSS score of 8.1, indicating a high impact if exploited.
Affected Systems
The affected products are Mozilla Firefox ESR 140.6, Firefox 146, Thunderbird ESR 140.6, and Thunderbird 146. These versions are no longer maintained and were superseded by Firefox 147, Firefox ESR 140.7, Thunderbird 147, and Thunderbird ESR 140.7, which contain the fixes.
Risk and Exploitability
The CVSS score reflects significant confidentiality, integrity, and availability risks. The EPSS score is below 1 %, suggesting the likelihood of active exploitation is low. It is not listed in the CISA KEV catalog. The attack vector is likely remote, with an attacker delivering crafted content (e.g., HTML, PDF, or other files) to the compromised browser or email client.
OpenCVE Enrichment
Debian DLA
Debian DSA
Ubuntu USN