Description
An error in the ECMA-262 specification relating to Async Generators could have resulted in a type confusion, potentially leading to memory corruption and an exploitable crash. This vulnerability affects Firefox < 128, Firefox ESR < 115.13, Thunderbird < 115.13, and Thunderbird < 128.
References (6)
Scores
CVSS v3
7.5
EPSS
0.0028
EPSS Percentile
51.0%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-843
CWE-476
Status
published
Products (3)
mozilla/firefox
< 115.13.0
mozilla/firefox
< 128.0
mozilla/thunderbird
< 115.13.0
Published
Sep 06, 2024
Tracked Since
Feb 18, 2026