Impact
Memory safety bugs were identified in Mozilla Thunderbird 140.10 and Thunderbird 150. The defects could corrupt process memory and, with sufficient effort, allow an attacker to execute arbitrary code. Although Thunderbird is the primary affected product, the same patch set that fixed these issues also addresses Firefox 151, Firefox ESR 115.36, and Firefox ESR 140.11.
Affected Systems
Affected products include Mozilla Thunderbird, specifically versions 140.10 and 150. The vulnerability was addressed in Thunderbird 151 and Thunderbird 140.11. The fix was also incorporated into multiple Firefox releases (Firefox 151, Firefox ESR 115.36, and Firefox ESR 140.11) at the time of the advisory, though those Firefox versions were not reported as directly impacted by the memory safety bugs.
Risk and Exploitability
EPSS data is unavailable and the vulnerability is not listed in the CISA KEV catalog. The CVE lists a CVSS score of 9.8, indicating high severity. The attack vector is not specified; it is inferred that the exploitation could arise from processing untrusted content, whether locally or remotely. Due to the lack of publicly reported exploitation, the risk assessment relies solely on the described vulnerability features.
OpenCVE Enrichment