Mozilla Firefox
cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*
- < 140
A use-after-free vulnerability has been identified in the FontFaceSet component of Mozilla Firefox and Firefox Extended Support Release (ESR). This vulnerability can lead to a crash that may be exploitable. It affects Firefox versions prior to 140, as well as Firefox ESR versions prior to 115.25 and 128.12.
Exploitation of this vulnerability can cause a crash, with the potential for exploitation to execute arbitrary code.
Users can upgrade to Firefox 140 or Firefox ESR 115.25 or 128.12 to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.