Unexpected marking work at the start of sweeping could have led to a use-after-free. This vulnerability affects Firefox < 129, Firefox ESR < 115.14, Firefox ESR < 128.1, Thunderbird < 128.1, and Thunderbird < 115.14.
2024-08-06T13:15:57.543
2025-03-18T19:15:47.403
Modified
CVSSv3.1: 8.8 (HIGH)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | mozilla | firefox | < 129.0 | Yes |
Application | mozilla | firefox_esr | < 115.14.0 | Yes |
Application | mozilla | firefox_esr | 128.0 | Yes |
Application | mozilla | thunderbird | < 115.14.0 | Yes |
Application | mozilla | thunderbird | 128.0.1 | Yes |