Impact
Memory safety bugs were discovered in several Mozilla products, including Firefox ESR 115.34.0, Firefox ESR 140.9.0, Thunderbird ESR 140.9.0, Firefox 149.0.1, and Thunderbird 149.0.1. These defects may cause memory corruption, and it is presumed that with sufficient effort they could be leveraged to execute arbitrary code. The vulnerability carries a CVSS score of 9.8, indicating a severe impact on confidentiality, integrity, and availability if exploited.
Affected Systems
Mozilla Firefox and Thunderbird are affected. The specific affected builds are Firefox ESR 115.34.0 and 140.9.0, Thunderbird ESR 140.9.0, Firefox 149.0.1, and Thunderbird 149.0.1. The issue has already been fixed in the following releases: Firefox 149.0.2, Firefox ESR 115.34.1, Firefox ESR 140.9.1, Thunderbird 149.0.2, and Thunderbird 140.9.1.
Risk and Exploitability
The vulnerability scores an EPSS of less than 1%, implying a low probability of exploitation in the wild. It is not listed in the CISA Known Exploited Vulnerabilities catalog. The lack of publicly documented exploit code and the nature of the bug suggest that the attack vector would most likely be local or require user interaction, although remote exploitation cannot be definitively ruled out without additional information. The high CVSS score reflects the potential for arbitrary code execution if successfully abused.
OpenCVE Enrichment
Debian DLA
Debian DSA