Описание
Use-after-free in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.
Ссылки
- Permissions Required
- Vendor Advisory
- Vendor Advisory
- Vendor Advisory
- Vendor Advisory
- Vendor Advisory
- Vendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 140.14.0 (исключая)Версия от 141.0.0 (включая) до 153.1.0 (исключая)Версия до 140.14.0 (исключая)Версия от 141.0 (включая) до 153.1.0 (исключая)
Одно из
cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*
EPSS
Процентиль: 33%
0.00403
Низкий
9.8 Critical
CVSS3
Дефекты
CWE-416
CWE-416
Связанные уязвимости
CVSS3: 9.8
ubuntu
9 дней назад
(Use-after-free in the JavaScript: WebAssembly component. This vulnerab ...)
CVSS3: 7.5
redhat
10 дней назад
Use-after-free in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.
CVSS3: 9.8
debian
10 дней назад
Use-after-free in the JavaScript: WebAssembly component. This vulnerab ...
CVSS3: 9.8
github
10 дней назад
Use-after-free in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, and Firefox ESR 153.1.
EPSS
Процентиль: 33%
0.00403
Низкий
9.8 Critical
CVSS3
Дефекты
CWE-416
CWE-416