Mozilla Firefox and Firefox ESR Incorrect Boundary Conditions and Uninitialized Memory Vulnerability in the JavaScript Engine Component

Vulnerability

A vulnerability exists in the JavaScript Engine component of Mozilla Firefox and Firefox ESR, specifically in versions prior to Firefox 149 and Firefox ESR prior to 140.9. The issue arises from incorrect boundary conditions and uninitialized memory, which could potentially be exploited.

Impact

Exploitation of this vulnerability could lead to memory corruption, with evidence suggesting that such corruption could be manipulated to execute arbitrary code.

Remediation

Users can upgrade to Firefox 149 or Firefox ESR 140.9 to address this vulnerability.

Added: Mar 24, 2026, 1:32 PM
Updated: Mar 24, 2026, 1:32 PM

Vulnerability Rating

Custom Algorithm
spread
8.4
impact
0.6
exploitability
4.4
remediation
7.7
relevance
4.6
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.