Mozilla Firefox
cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*
- < 148
A sandbox escape vulnerability has been identified in the WebRender component of Mozilla Firefox and Thunderbird. This issue arises from incorrect boundary conditions, allowing for potential unauthorized access or actions within the application sandbox. The vulnerability affects multiple versions of Firefox and Thunderbird, including Firefox versions prior to 148, Firefox ESR versions prior to 115.33 and 140.8, as well as Thunderbird versions prior to 148 and 140.8.
Exploitation of this vulnerability leads to a sandbox escape, allowing potentially malicious actions or access to resources that are normally restricted within the application sandbox.
Users can upgrade to Firefox 148 or Thunderbird 148. For Firefox ESR users, version 140.8 is available. Instructions for updating can be found in the Firefox Release Notes and the Thunderbird Release Notes.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.