Impact
The vulnerability is a use‑after‑free bug in the DOM: Core & HTML component of Mozilla products. A malicious page can trigger the browser to free an object and later access it again, producing memory corruption. This flaw can cause the browser to crash or, in some cases, allow an attacker to execute arbitrary code within the context of the page. The weakness is classified as CWE‑416.
Affected Systems
Mozilla Firefox releases prior to version 155, and the Firefox ESR 140.15 and 153.2 branches, as well as Mozilla Thunderbird releases prior to version 155 and the Thunderbird ESR 140.15 and 153.2 branches, are vulnerable. All later releases contain the fix.
Risk and Exploitability
The CVSS score of 5.4 indicates a moderate severity. The EPSS score is not available and the vulnerability is not listed in CISA’s KEV catalog. Because the flaw is a memory corruption error that can be triggered by a malicious web page, the likely attack vector is a crafted site that causes the browser to free an object and then reuse it. No public workaround exists, so the safest mitigation is to apply the vendor‑supplied update.
OpenCVE Enrichment
Debian DLA
Debian DSA