Impact
Memory safety bugs were present in Mozilla Firefox ESR 115.35, Firefox ESR 140.10, and Firefox 150. The defects could corrupt process memory and, with sufficient effort, allow an attacker to execute arbitrary code. The same fixes also address Firefox 151, Firefox ESR 115.36, and Firefox ESR 140.11, and were applied to Mozilla Thunderbird in versions 151 and 140.11. These defects correspond to buffer overflow (CWE-119) and out-of-bounds write (CWE-787) vulnerabilities.
Affected Systems
Affected products include Mozilla Firefox ESR 115.35, Firefox ESR 140.10, and Firefox 150. The vulnerability was fixed by upgrading to Firefox 151, Firefox ESR 115.36, or Firefox ESR 140.11. The same fixes were applied to Mozilla Thunderbird, with Thunderbird 151 and Thunderbird 140.11 addressing the same memory safety issues. Earlier Thunderbird releases were not explicitly listed but are presumed to be affected by the same underlying flaw.
Risk and Exploitability
The EPSS score is reported as less than 1%, indicating a low but non‑zero exploitation probability, and the weakness is not listed in the CISA KEV catalog. The CVSS score of 8.8 indicates high severity. The attack vector is not specified; it is inferred that the exploitation could arise from processing untrusted content, whether locally or remotely. Due to the lack of publicly reported exploitation, the risk assessment relies solely on the described vulnerability features.
OpenCVE Enrichment
Debian DLA
Debian DSA