Impact
The vulnerability arises from internally identified bugs in Thunderbird 154, Thunderbird ESR 153.1, and Thunderbird ESR 140.14 that caused memory corruption or other security-relevant defects. Some of these bugs could be leveraged, with sufficient effort, to achieve arbitrary code execution or to cause denial of service. The description acknowledges a potential risk but does not confirm a known exploit. Therefore, the primary impact is the possibility of remote code execution or system compromise.
Affected Systems
Both Mozilla Firefox and Mozilla Thunderbird are affected when running versions prior to Firefox 155, Firefox ESR 140.15, or Firefox ESR 153.2, and Thunderbird 155, Thunderbird ESR 140.15, or Thunderbird ESR 153.2. The bugs are present in Firefox 154, Firefox ESR 153.1, Firefox ESR 140.14, Thunderbird 154, Thunderbird ESR 153.1, and Thunderbird ESR 140.14. The affected products are specifically Mozilla:Firefox and Mozilla:Thunderbird with the stated versions.
Risk and Exploitability
The CVSS score of 9.8 denotes a critical impact, while the EPSS score is below 1%, indicating a low likelihood of widespread exploitation at present. The vulnerability is not listed in Memory corruption defects of this nature can allow an attacker to achieve arbitrary code execution if the conditions for exploitation are met. The lack of publicly documented proof of exploitation means the actual risk depends on whether an attacker can successfully leverage the defects, but the high severity score justifies treating it as a high‑risk issue.
OpenCVE Enrichment
Debian DLA
Debian DSA