Mozilla Firefox
cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*
- < 138
A vulnerability exists in Mozilla Thunderbird and Firefox due to improper null checks during XPath attribute access. This oversight can cause undefined behavior, allowing out-of-bounds read access that may lead to memory corruption. The issue is present in Firefox versions prior to 138, Firefox ESR versions prior to 128.10, and Thunderbird versions prior to 138 and 128.10.
Exploitation of this vulnerability could result in out-of-bounds read access and potentially corrupt memory, creating a risk of arbitrary code execution.
Users can upgrade to Thunderbird 138 or Firefox 138 to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.