Impact
These bugs were discovered inside Firefox 154 and various ESR releases, where they caused memory corruption or similar security‑relevant defects. The description indicates that, with sufficient effort, these defects could be exploited to gain unintended privileges or execute arbitrary code. The nature of the bugs suggests an out‑of‑bounds memory write or overflow that could be triggered by crafted content or data.
Affected Systems
The affected builds are Firefox 154, Firefox ESR 153.1, Firefox ESR 140.14 and Firefox ESR 115.39. All of these are upstream or ESR releases that were superseded by newer security‑patched versions: Firefox 155, Firefox ESR 115.40, Firefox ESR 140.15 and Firefox ESR 153.2.
Risk and Exploitability
A CVSS score is not available, and EPSS data is missing, but the presence of potential memory corruption raises the risk level to high. No listing in CISA KEV yet, but the severity of the underlying bug type implies that the vulnerability is exploitable if an attacker can craft input that triggers the memory corruption. The likely attack vector is local or remote web page content processing, though the exact path is not detailed in the provided data.
OpenCVE Enrichment