Mozilla Firefox
cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*
- < 144
A vulnerability exists in Mozilla Firefox and Thunderbird that allows a compromised web process to perform out-of-bounds reads and writes in a more privileged process. This exploitation is achieved through manipulated WebGL textures. The issue affects multiple versions of Firefox and Thunderbird, with specific version ranges detailed in the advisory.
Exploitation of this vulnerability could lead to memory corruption, with evidence suggesting that such corruption could be leveraged to execute arbitrary code.
Users can upgrade to Firefox 144, Firefox ESR 140.4, Thunderbird 144, or Thunderbird ESR 140.4 to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.