Impact
The CVE documents an unspecified issue within Mozilla Firefox's JavaScript engine that was fixed in Firefox 150.0.3, Firefox ESR 115.36, and Firefox ESR 140.11. No explicit impact is described by Mozilla; the associated CWE identifiers (CWE‑119, CWE‑20, CWE‑475, CWE‑79) suggest potential weaknesses such as buffer overflows, input validation failures, or cross‑site scripting, but the real impact on confidentiality, integrity, or availability is not stated.
Affected Systems
All Mozilla Firefox installations running any version prior to 150.0.3 and all Mozilla Thunderbird installations running any version prior to 140.11 are affected. No other vendors or products are reported to be vulnerable.
Risk and Exploitability
The CVSS score of 5.3 denotes moderate severity, while the EPSS score of < 1% indicates a very low but non‑zero likelihood of exploitation. The vulnerability is not listed in CISA's KEV catalog. The likely attack vector is a web‑based or browser‑context delivery of malicious JavaScript, although no concrete exploitation is documented at this time.
OpenCVE Enrichment
Debian DLA
Debian DSA