Impact
Memory safety bugs were discovered in Mozilla Thunderbird ESR 140.12, causing memory corruption. The bugs could allow an attacker to execute arbitrary code if sufficient effort is applied to trigger the corruption. The issue is classified as a buffer over-read/write (CWE-119).
Affected Systems
The vulnerability affects Mozilla Thunderbird running version 140.12. The same bugs also appear in Mozilla Firefox ESR 115.38 and 140.13, but the original discovery was specific to Thunderbird. Upgrading to Thunderbird 140.13 or newer, or to Firefox ESR 115.38 or newer, removes the flaw.
Risk and Exploitability
The CVSS score of 9.8 indicates critical severity. The EPSS score of < 1% suggests that automated exploitation attempts are unlikely at present. The vulnerability is not listed in the CISA KEV catalog. Because the bugs involve memory corruption, the potential for arbitrary code execution exists, but the exact exploitation conditions are not detailed in the advisory; it is presumed that a malicious payload would be required.
OpenCVE Enrichment
Debian DLA
Debian DSA