Mozilla Firefox ESR and Thunderbird Memory Safety Vulnerability Allowing Arbitrary Code Execution

Vulnerability

A memory safety vulnerability has been identified in Firefox ESR versions prior to 128.10 and Thunderbird versions prior to 128.10. This vulnerability exhibits signs of memory corruption, which could potentially be exploited to execute arbitrary code with sufficient effort.

Impact

Exploitation of this vulnerability could lead to arbitrary code execution.

Remediation

Users can upgrade to Firefox ESR 128.10 or Thunderbird 128.10 to address this vulnerability.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
7.8
impact
10.0
exploitability
4.4
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.