When receiving rendering data over IPC `mStream` could have been destroyed when initialized, which could have led to a use-after-free causing a potentially exploitable crash. This vulnerability affects Firefox < 117, Firefox ESR < 102.15, Firefox ESR < 115.2, Thunderbird < 102.15, and Thunderbird < 115.2.
2023-09-11T08:15:07.847
2024-11-21T08:35:27.493
Modified
CVSSv3.1: 6.5 (MEDIUM)
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | mozilla | firefox | < 117.0 | Yes |
| Application | mozilla | firefox | < 115.2 | Yes |
| Application | mozilla | firefox_esr | < 102.15 | Yes |
| Application | mozilla | thunderbird | < 115.2 | Yes |