Mozilla Firefox ESR
cpe:2.3:a:mozilla:firefox_esr:*:*:*:*:*:*:*
- < 128.10
- < 115.23
A local code execution vulnerability has been identified in the 'copy as cURL' feature of Mozilla Firefox and Thunderbird. This issue arises from inadequate escaping of special characters, particularly the ampersand, which could allow an attacker to manipulate the command and execute code on the user's system. The vulnerability is present in Firefox for Windows and affects several versions of Firefox ESR and Thunderbird.
Exploitation of this vulnerability could lead to unauthorized local code execution on the user's system.
Users can update to Firefox ESR 128.10, Firefox ESR 115.23, or Thunderbird 128.10 to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.