Impact
The report describes several internal bugs affecting Thunderbird 154 that manifest as memory corruption or other security‑relevant defects. These weaknesses, associated with CWE‑119 and CWE‑200, could allow an attacker to compromise the application process or alter sensitive data in memory if the vulnerable code path can be successfully triggered.
Affected Systems
Mozilla Thunderbird 154 and Mozilla Firefox 154 are affected. The vulnerabilities were addressed in Thunderbird 155 and Firefox 155. Any installation of the affected versions, either standalone or bundled with other Mozilla releases, remains vulnerable until updated.
Risk and Exploitability
The CVSS score of 9.8 indicates critical severity, while the EPSS score of less than 1% suggests a very low likelihood of exploitation at this time. The flaw is not listed in CISA’s KEV catalog, implying no publicly known active exploits. The exact attack vector is not specified; however, based on the memory corruption nature and the application context, it is reasonable to infer that the flaw could be triggered by a maliciously crafted email, attachment, or message that a user opens, potentially requiring local user interaction. If the vulnerable code processes external network data, remote exploitation could also be conceivable. An attacker who succeeds would obtain full control of the Thunderbird or Firefox process.
OpenCVE Enrichment