Impact
Memory safety bugs were present in older releases of Mozilla Firefox: Firefox ESR 115.35.1, Firefox ESR 140.10.1, and Firefox 150.0.1. The bugs exhibit out‑of‑bounds reads, writes, and use‑after‑free conditions that can corrupt memory. The vendor presumes that with sufficient effort, these defects could be exploited to run arbitrary code within the affected application’s process.
Affected Systems
End users running Mozilla Thunderbird ESR 140.10.1, Thunderbird 150.0.1, Firefox 150.0.1, Firefox ESR 140.10.1 or Firefox ESR 115.35.1 remain vulnerable. The issues were addressed in Thunderbird 140.10.2 and 150.0.2, and in Firefox 150.0.2, Firefox ESR 140.10.2 and Firefox ESR 115.35.2. Any installation that has not yet migrated to these releases continues to be at risk.
Risk and Exploitability
The CVSS score of 8.1 indicates a high severity, while the EPSS score of <1% suggests a low likelihood of exploitation in the wild. The vulnerability is not listed in CISA’s KEV catalog and no public exploits are known. The flaw does not provide direct network access or privilege escalation; it requires crafted email or web content that is processed by the affected browser or mail client to trigger the memory corruption and potentially hijack control flow.
OpenCVE Enrichment
Debian DLA
Debian DSA