Mozilla Firefox
cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*, +2 more
- < 134
A vulnerability exists in Mozilla Firefox versions prior to 134, Firefox ESR versions prior to 128.6, and Thunderbird versions prior to 134 and 128.6. This vulnerability arises from a compartment mismatch that can occur when a JavaScript module is parsed as JSON, potentially leading to cross-compartment access and a use-after-free condition.
Exploitation of this vulnerability could result in a use-after-free condition, commonly associated with memory corruption issues that can be exploited to execute arbitrary code.
Users can upgrade to Firefox 134, Firefox ESR 128.6, Thunderbird 134, or Thunderbird 128.6 to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.