Mozilla Firefox
cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*, +1 more
- < 136
A vulnerability exists in Mozilla Firefox versions prior to 136, Firefox ESR versions prior to 128.8, and Thunderbird versions prior to 136 and 128.8 ESR. This issue allows for the interruption of RegExp bailout processing, enabling the execution of additional JavaScript. Such interference could trigger garbage collection at unexpected times, potentially leading to memory management issues.
Exploitation of this vulnerability could disrupt normal JavaScript execution and memory management, causing unexpected behavior in the application.
Users can upgrade to Firefox 136, Firefox ESR 128.8, or Thunderbird 136 or 128.8 ESR to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.