Mozilla Firefox
cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*
- < 146
A Just-In-Time (JIT) miscompilation vulnerability has been identified in the JavaScript engine of Mozilla Firefox. This issue affects Firefox versions prior to 146 and Firefox ESR versions prior to 140.6. The vulnerability arises from incorrect optimizations in the JIT compilation process, which could potentially be exploited to cause unexpected behavior in the JavaScript engine.
Exploitation of this vulnerability could lead to JIT spraying, a technique that manipulates the JIT compiler's optimization process. This could potentially be used to execute arbitrary code or cause a crash.
Users can upgrade to Firefox 146 or Firefox ESR 140.6 to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.