Mozilla Firefox
cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*
- < 135
A use-after-free vulnerability has been identified in Mozilla Firefox and Thunderbird applications, specifically in versions prior to Firefox 135, Firefox ESR 115.20, Firefox ESR 128.7, Thunderbird 128.7, and Thunderbird 135. This vulnerability arises from the improper handling of crafted XSLT data, which could lead to a crash that might be exploitable.
Exploitation of this vulnerability could lead to a crash of the application, with the potential for arbitrary code execution.
Users can upgrade to Firefox 135, Firefox ESR 115.20, or Thunderbird 135 to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.