Impact
Memory safety bugs were discovered in Firefox ESR 115.37, Firefox ESR 140.12, and Firefox 152. The same set of buffer overflow or bounds‑check failures (CWE‑119 and CWE‑120) also affect the corresponding Thunderbird releases. These bugs corrupt memory when the applications process crafted data; when successfully triggered, the resulting memory corruption could allow an attacker to execute arbitrary code on the affected device, compromising confidentiality, integrity, and availability.
Affected Systems
The vulnerability affects Mozilla Firefox and Mozilla Thunderbird. Versions prior to the patched releases—Firefox ESR 115.37, Firefox ESR 140.12, and Firefox 152—are susceptible. The bugs also exist in Thunderbird releases before 140.13 and 153. The fixes are included in Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13, Thunderbird 153, and Thunderbird ESR 140.13.
Risk and Exploitability
The CVSS score of 9.8 indicates critical severity, yet the EPSS score of less than 1% demonstrates a very low probability of exploitation in the wild. The vulnerability is not listed in CISA’s KEV catalog, meaning no known active exploits are reported. Based on the description, it is inferred that the most likely attack vectors involve exposure to maliciously crafted web content or a specially crafted email attachment that, when rendered by the vulnerable browser or email client, triggers the memory corruption. In addition, user interaction such as visiting a site or opening an email is typically required for exploitation.
OpenCVE Enrichment
Debian DLA
Debian DSA