Mozilla Firefox
cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*, +2 more
- < 136
A use-after-free vulnerability has been identified in the content process side of a WebTransport connection in Mozilla Firefox and Thunderbird. This issue can lead to a potentially exploitable crash. The vulnerability affects Firefox versions prior to 136, Firefox ESR versions prior to 115.21 and 128.8, as well as Thunderbird versions prior to 136 and 128.8.
Exploitation of this vulnerability can cause a crash, with the potential for exploitation to execute arbitrary code.
Users can upgrade to Firefox 136, Firefox ESR 115.21 or 128.8, or Thunderbird 136 or 128.8 to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.