Impact
The issue is incorrect boundary conditions in the JavaScript engine’s just-in-time (JIT) component. The description does not mention the precise impact, yet such a defect, a CWE-119 and CWE-787 vulnerability, could lead to memory corruption or instability.
Affected Systems
Mozilla Firefox and Mozilla Thunderbird are affected. Versions of Firefox earlier than 150.0.3, and any Firefox ESR releases before 115.36 or before 140.11, are vulnerable, because the defect was fixed in Firefox 150.0.3, Firefox ESR 115.36, and Firefox ESR 140.11. Thunderbird releases older than 140.11 are also affected, as the fix came in Thunderbird 140.11. No other products or versions are explicitly mentioned.
Risk and Exploitability
The vulnerability is not listed in the CISA KEV catalog and the EPSS score of < 1% indicates a very low probability of exploitation. The CVSS score of 6.5 indicates a moderate severity threat. Potential exploitation would likely occur via malicious web content that triggers the vulnerable path in the JIT compiler. Based on the information, it is inferred that an attacker could induce memory corruption by delivering crafted JavaScript to a vulnerable browser instance.
OpenCVE Enrichment
Debian DLA
Debian DSA