Inappropriate coding practices In firefox-esr
Description
Memory safety bugs present in Firefox ESR 140.8, Thunderbird ESR 140.8, Firefox 148 and Thunderbird 148. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
debian 12 | =102.11.0esr-1 || =102.12.0esr-1 || =102.12.0esr-1~deb10u1 || =102.12.0esr-1~deb11u1 || =102.12.0esr-1~deb12u1 || =102.13.0esr-1 || =102.13.0esr-1~deb10u1 || =102.13.0esr-1~deb11u1 || =102.13.0esr-1~deb12u1 || =102.14.0esr-1~deb10u1 || =102.14.0esr-1~deb11u1 || =102.14.0esr-1~deb12u1 || =102.15.0esr-1~deb10u1 || =102.15.0esr-1~deb11u1 || =102.15.0esr-1~deb12u1 || =102.15.1esr-1~deb10u1 || =102.15.1esr-1~deb11u1 || =102.15.1esr-1~deb12u1 || =115.0.2esr-1 || =115.1.0esr-1 || =115.10.0esr-1 || =115.10.0esr-1~deb10u1 || =115.10.0esr-1~deb11u1 || =115.10.0esr-1~deb12u1 || =115.11.0esr-1 || =115.11.0esr-1~deb10u1 || =115.11.0esr-1~deb11u1 || =115.11.0esr-1~deb12u1 || =115.12.0esr-1 || =115.12.0esr-1~deb10u1 || =115.12.0esr-1~deb11u1 || =115.12.0esr-1~deb12u1 || =115.13.0esr-1 || =115.13.0esr-1~deb11u1 || =115.13.0esr-1~deb12u1 || =115.13.0esr-2 || =115.14.0esr-1 || =115.14.0esr-1~deb11u1 || =115.14.0esr-1~deb12u1 || =115.15.0esr-1 || =115.15.0esr-1~deb11u1 || =115.15.0esr-1~deb12u1 || =115.2.0esr-1 || =115.2.1esr-1 || =115.3.0esr-1 || =115.3.0esr-1~deb10u1 || =115.3.0esr-1~deb11u1 || =115.3.0esr-1~deb12u1 || =115.3.1esr-1~deb10u1 || =115.3.1esr-1~deb11u1 || =115.4.0esr-1 || =115.4.0esr-1~deb10u1 || =115.4.0esr-1~deb11u1 || =115.4.0esr-1~deb12u1 || =115.5.0esr-1 || =115.5.0esr-1~deb10u1 || =115.5.0esr-1~deb11u1 || =115.5.0esr-1~deb12u1 || =115.6.0esr-1 || =115.6.0esr-1~deb10u1 || =115.6.0esr-1~deb11u1 || =115.6.0esr-1~deb12u1 || =115.7.0esr-1 || =115.7.0esr-1~deb10u1 || =115.7.0esr-1~deb11u1 || =115.7.0esr-1~deb12u1 || =115.8.0esr-1 || =115.8.0esr-1~deb10u1 || =115.8.0esr-1~deb11u1 || =115.8.0esr-1~deb12u1 || =115.9.0esr-1 || =115.9.0esr-1~deb11u1 || =115.9.0esr-1~deb12u1 || =115.9.0esr-2 || =115.9.1esr-1 || =115.9.1esr-1~deb10u1 || =115.9.1esr-1~deb11u1 || =115.9.1esr-1~deb12u1 || =128.10.0esr-1 || =128.10.0esr-1~deb12u1 || =128.10.1esr-1 || =128.10.1esr-1~deb11u1 || =128.10.1esr-1~deb12u1 || =128.11.0esr-1 || =128.11.0esr-1~deb11u1 || =128.11.0esr-1~deb12u1 || =128.12.0esr-1 || =128.12.0esr-1~deb11u1 || =128.12.0esr-1~deb12u1 || =128.13.0esr-1 || =128.13.0esr-1~deb11u1 || =128.13.0esr-1~deb12u1 || =128.14.0esr-1 || =128.14.0esr-1~deb11u1 || =128.14.0esr-1~deb12u1 || =128.14.0esr-1~deb13u1 || =128.3.0esr-1 || =128.3.0esr-1~deb11u1 || =128.3.0esr-1~deb11u2 || =128.3.0esr-1~deb12u1 || =128.3.0esr-2 || =128.3.1esr-1 || =128.3.1esr-1~deb11u1 || =128.3.1esr-1~deb12u1 || =128.3.1esr-2 || =128.4.0esr-1 || =128.4.0esr-1~deb11u1 || =128.4.0esr-1~deb12u1 || =128.5.0esr-1 || =128.5.0esr-1~deb11u1 || =128.5.0esr-1~deb12u1 || =128.5.1esr-1 || =128.6.0esr-1 || =128.6.0esr-1~deb11u1 || =128.6.0esr-1~deb11u2 || =128.6.0esr-1~deb11u3 || =128.6.0esr-1~deb12u1 || =128.6.0esr-2 || =128.6.0esr-3 || =128.6.0esr-4 || =128.7.0esr-1 || =128.7.0esr-1~deb11u1 || =128.7.0esr-1~deb12u1 || =128.8.0esr-1 || =128.8.0esr-1~deb11u1 || =128.8.0esr-1~deb12u1 || =128.9.0esr-1 || =128.9.0esr-1~deb11u1 || =128.9.0esr-1~deb12u1 || =128.9.0esr-2 || =140.3.0esr-1 || =140.3.0esr-1~deb11u1 || =140.3.0esr-1~deb11u2 || =140.3.0esr-1~deb12u1 || =140.3.0esr-1~deb13u1 || =140.3.0esr-2 || =140.3.1esr-1 || =140.3.1esr-1~deb11u1 || =140.3.1esr-1~deb12u1 || =140.3.1esr-1~deb13u1 || =140.3.1esr-2 || =140.4.0esr-1 || =140.4.0esr-1~deb11u1 || =140.4.0esr-1~deb12u1 || =140.4.0esr-1~deb13u1 || =140.5.0esr-1 || =140.5.0esr-1~deb11u1 || =140.5.0esr-1~deb12u1 || =140.5.0esr-1~deb13u1 || =140.6.0esr-1 || =140.6.0esr-1~deb11u1 || =140.6.0esr-1~deb12u1 || =140.6.0esr-1~deb13u1 || =140.7.0esr-1 || =140.7.0esr-1~deb11u1 || =140.7.0esr-1~deb12u1 || =140.7.0esr-1~deb13u1 || =140.8.0esr-1 || =140.8.0esr-1~deb11u1 || =140.8.0esr-1~deb12u1 || =140.8.0esr-1~deb13u1 || =140.9.0esr-1~deb11u1 || >=0 <140.9.0esr-1~deb12u1 | 140.9.0esr-1~deb12u1 | |
debian 13 | =128.13.0esr-1 || =128.14.0esr-1 || =128.14.0esr-1~deb11u1 || =128.14.0esr-1~deb12u1 || =128.14.0esr-1~deb13u1 || =140.3.0esr-1 || =140.3.0esr-1~deb11u1 || =140.3.0esr-1~deb11u2 || =140.3.0esr-1~deb12u1 || =140.3.0esr-1~deb13u1 || =140.3.0esr-2 || =140.3.1esr-1 || =140.3.1esr-1~deb11u1 || =140.3.1esr-1~deb12u1 || =140.3.1esr-1~deb13u1 || =140.3.1esr-2 || =140.4.0esr-1 || =140.4.0esr-1~deb11u1 || =140.4.0esr-1~deb12u1 || =140.4.0esr-1~deb13u1 || =140.5.0esr-1 || =140.5.0esr-1~deb11u1 || =140.5.0esr-1~deb12u1 || =140.5.0esr-1~deb13u1 || =140.6.0esr-1 || =140.6.0esr-1~deb11u1 || =140.6.0esr-1~deb12u1 || =140.6.0esr-1~deb13u1 || =140.7.0esr-1 || =140.7.0esr-1~deb11u1 || =140.7.0esr-1~deb12u1 || =140.7.0esr-1~deb13u1 || =140.8.0esr-1 || =140.8.0esr-1~deb11u1 || =140.8.0esr-1~deb12u1 || =140.8.0esr-1~deb13u1 || =140.9.0esr-1~deb11u1 || =140.9.0esr-1~deb12u1 || >=0 <140.9.0esr-1~deb13u1 | 140.9.0esr-1~deb13u1 | |
debian 14 | =128.13.0esr-1 || =128.14.0esr-1 || =128.14.0esr-1~deb11u1 || =128.14.0esr-1~deb12u1 || =128.14.0esr-1~deb13u1 || =140.3.0esr-1 || =140.3.0esr-1~deb11u1 || =140.3.0esr-1~deb11u2 || =140.3.0esr-1~deb12u1 || =140.3.0esr-1~deb13u1 || =140.3.0esr-2 || =140.3.1esr-1 || =140.3.1esr-1~deb11u1 || =140.3.1esr-1~deb12u1 || =140.3.1esr-1~deb13u1 || =140.3.1esr-2 || =140.4.0esr-1 || =140.4.0esr-1~deb11u1 || =140.4.0esr-1~deb12u1 || =140.4.0esr-1~deb13u1 || =140.5.0esr-1 || =140.5.0esr-1~deb11u1 || =140.5.0esr-1~deb12u1 || =140.5.0esr-1~deb13u1 || =140.6.0esr-1 || =140.6.0esr-1~deb11u1 || =140.6.0esr-1~deb12u1 || =140.6.0esr-1~deb13u1 || =140.7.0esr-1 || =140.7.0esr-1~deb11u1 || =140.7.0esr-1~deb12u1 || =140.7.0esr-1~deb13u1 || =140.8.0esr-1 || =140.8.0esr-1~deb11u1 || =140.8.0esr-1~deb12u1 || =140.8.0esr-1~deb13u1 || =140.9.0esr-1~deb11u1 || =140.9.0esr-1~deb12u1 || =140.9.0esr-1~deb13u1 || >=0 <140.9.0esr-1 | 140.9.0esr-1 | |
debian 13 | =1:128.13.0esr-1 || =1:128.14.0esr-1 || =1:128.14.0esr-1~deb11u1 || =1:128.14.0esr-1~deb12u1 || =1:128.14.0esr-1~deb13u1 || =1:129.0~b6-1 || =1:130.0~b3-1 || =1:132.0~b6-1 || =1:135.0-1 || =1:136.0-1 || =1:137.0-1 || =1:138.0-1 || =1:140.0.1esr-1 || =1:140.1.0esr-1 || =1:140.1.1esr-1 || =1:140.2.0esr-1 || =1:140.3.0esr-1 || =1:140.3.0esr-1~deb11u1 || =1:140.3.0esr-1~deb12u1 || =1:140.3.0esr-1~deb13u1 || =1:140.3.1esr-1 || =1:140.4.0esr-1 || =1:140.4.0esr-1~deb11u1 || =1:140.4.0esr-1~deb12u1 || =1:140.4.0esr-1~deb13u1 || =1:140.5.0esr-1 || =1:140.5.0esr-1~deb11u1 || =1:140.5.0esr-1~deb12u1 || =1:140.5.0esr-1~deb13u1 || =1:140.6.0esr-1 || =1:140.6.0esr-1~deb11u1 || =1:140.6.0esr-1~deb12u1 || =1:140.6.0esr-1~deb13u1 || =1:140.7.0esr-1 || =1:140.7.0esr-1~deb11u1 || =1:140.7.0esr-1~deb12u1 || =1:140.7.0esr-1~deb13u1 || =1:140.7.1esr-1 || =1:140.7.1esr-1~deb11u1 || =1:140.7.1esr-1~deb12u1 || =1:140.7.1esr-1~deb13u1 || =1:140.8.0esr-1 || =1:140.8.0esr-1~deb11u1 || =1:140.8.0esr-1~deb12u1 || =1:140.8.0esr-1~deb13u1 || =1:140.9.0esr-1~deb11u1 || =1:140.9.0esr-1~deb12u1 || >=0 <1:140.9.0esr-1~deb13u1 | 1:140.9.0esr-1~deb13u1 | |
rpm rhel10 | - | - | |
rpm rhel10 | - | - | |
rpm rhel10 | <0:140.9.0-1.el10_1 | 0:140.9.0-1.el10_1 | |
rpm rhel7 | - | - | |
rpm rhel9 | <0:140.9.0-1.el9_7 | 0:140.9.0-1.el9_7 | |
debian 11 | =102.1.0esr-1 || =102.1.0esr-2 || =102.10.0esr-1 || =102.10.0esr-1~deb10u1 || =102.10.0esr-1~deb11u1 || =102.11.0esr-1 || =102.11.0esr-1~deb10u1 || =102.11.0esr-1~deb11u1 || =102.12.0esr-1 || =102.12.0esr-1~deb10u1 || =102.12.0esr-1~deb11u1 || =102.12.0esr-1~deb12u1 || =102.13.0esr-1 || =102.13.0esr-1~deb10u1 || =102.13.0esr-1~deb11u1 || =102.13.0esr-1~deb12u1 || =102.14.0esr-1~deb10u1 || =102.14.0esr-1~deb11u1 || =102.14.0esr-1~deb12u1 || =102.15.0esr-1~deb10u1 || =102.15.0esr-1~deb11u1 || =102.15.0esr-1~deb12u1 || =102.15.1esr-1~deb10u1 || =102.15.1esr-1~deb11u1 || =102.15.1esr-1~deb12u1 || =102.2.0esr-1 || =102.3.0esr-1 || =102.3.0esr-1~deb10u1 || =102.3.0esr-1~deb10u2 || =102.3.0esr-1~deb11u1 || =102.4.0esr-1 || =102.4.0esr-1~deb10u1 || =102.4.0esr-1~deb11u1 || =102.5.0esr-1 || =102.5.0esr-1~deb10u1 || =102.5.0esr-1~deb11u1 || =102.6.0esr-1 || =102.6.0esr-1~deb10u1 || =102.6.0esr-1~deb11u1 || =102.7.0esr-1 || =102.7.0esr-1~deb10u1 || =102.7.0esr-1~deb11u1 || =102.8.0esr-1 || =102.8.0esr-1~deb10u1 || =102.8.0esr-1~deb11u1 || =102.9.0esr-1 || =102.9.0esr-1~deb10u1 || =102.9.0esr-1~deb11u1 || =102.9.0esr-2 || =115.0.2esr-1 || =115.1.0esr-1 || =115.10.0esr-1 || =115.10.0esr-1~deb10u1 || =115.10.0esr-1~deb11u1 || =115.10.0esr-1~deb12u1 || =115.11.0esr-1 || =115.11.0esr-1~deb10u1 || =115.11.0esr-1~deb11u1 || =115.11.0esr-1~deb12u1 || =115.12.0esr-1 || =115.12.0esr-1~deb10u1 || =115.12.0esr-1~deb11u1 || =115.12.0esr-1~deb12u1 || =115.13.0esr-1 || =115.13.0esr-1~deb11u1 || =115.13.0esr-1~deb12u1 || =115.13.0esr-2 || =115.14.0esr-1 || =115.14.0esr-1~deb11u1 || =115.14.0esr-1~deb12u1 || =115.15.0esr-1 || =115.15.0esr-1~deb11u1 || =115.15.0esr-1~deb12u1 || =115.2.0esr-1 || =115.2.1esr-1 || =115.3.0esr-1 || =115.3.0esr-1~deb10u1 || =115.3.0esr-1~deb11u1 || =115.3.0esr-1~deb12u1 || =115.3.1esr-1~deb10u1 || =115.3.1esr-1~deb11u1 || =115.4.0esr-1 || =115.4.0esr-1~deb10u1 || =115.4.0esr-1~deb11u1 || =115.4.0esr-1~deb12u1 || =115.5.0esr-1 || =115.5.0esr-1~deb10u1 || =115.5.0esr-1~deb11u1 || =115.5.0esr-1~deb12u1 || =115.6.0esr-1 || =115.6.0esr-1~deb10u1 || =115.6.0esr-1~deb11u1 || =115.6.0esr-1~deb12u1 || =115.7.0esr-1 || =115.7.0esr-1~deb10u1 || =115.7.0esr-1~deb11u1 || =115.7.0esr-1~deb12u1 || =115.8.0esr-1 || =115.8.0esr-1~deb10u1 || =115.8.0esr-1~deb11u1 || =115.8.0esr-1~deb12u1 || =115.9.0esr-1 || =115.9.0esr-1~deb11u1 || =115.9.0esr-1~deb12u1 || =115.9.0esr-2 || =115.9.1esr-1 || =115.9.1esr-1~deb10u1 || =115.9.1esr-1~deb11u1 || =115.9.1esr-1~deb12u1 || =128.10.0esr-1 || =128.10.0esr-1~deb12u1 || =128.10.1esr-1 || =128.10.1esr-1~deb11u1 || =128.10.1esr-1~deb12u1 || =128.11.0esr-1 || =128.11.0esr-1~deb11u1 || =128.11.0esr-1~deb12u1 || =128.12.0esr-1 || =128.12.0esr-1~deb11u1 || =128.12.0esr-1~deb12u1 || =128.13.0esr-1 || =128.13.0esr-1~deb11u1 || =128.13.0esr-1~deb12u1 || =128.14.0esr-1 || =128.14.0esr-1~deb11u1 || =128.14.0esr-1~deb12u1 || =128.14.0esr-1~deb13u1 || =128.3.0esr-1 || =128.3.0esr-1~deb11u1 || =128.3.0esr-1~deb11u2 || =128.3.0esr-1~deb12u1 || =128.3.0esr-2 || =128.3.1esr-1 || =128.3.1esr-1~deb11u1 || =128.3.1esr-1~deb12u1 || =128.3.1esr-2 || =128.4.0esr-1 || =128.4.0esr-1~deb11u1 || =128.4.0esr-1~deb12u1 || =128.5.0esr-1 || =128.5.0esr-1~deb11u1 || =128.5.0esr-1~deb12u1 || =128.5.1esr-1 || =128.6.0esr-1 || =128.6.0esr-1~deb11u1 || =128.6.0esr-1~deb11u2 || =128.6.0esr-1~deb11u3 || =128.6.0esr-1~deb12u1 || =128.6.0esr-2 || =128.6.0esr-3 || =128.6.0esr-4 || =128.7.0esr-1 || =128.7.0esr-1~deb11u1 || =128.7.0esr-1~deb12u1 || =128.8.0esr-1 || =128.8.0esr-1~deb11u1 || =128.8.0esr-1~deb12u1 || =128.9.0esr-1 || =128.9.0esr-1~deb11u1 || =128.9.0esr-1~deb12u1 || =128.9.0esr-2 || =140.3.0esr-1 || =140.3.0esr-1~deb11u1 || =140.3.0esr-1~deb11u2 || =140.3.0esr-1~deb12u1 || =140.3.0esr-1~deb13u1 || =140.3.0esr-2 || =140.3.1esr-1 || =140.3.1esr-1~deb11u1 || =140.3.1esr-1~deb12u1 || =140.3.1esr-1~deb13u1 || =140.3.1esr-2 || =140.4.0esr-1 || =140.4.0esr-1~deb11u1 || =140.4.0esr-1~deb12u1 || =140.4.0esr-1~deb13u1 || =140.5.0esr-1 || =140.5.0esr-1~deb11u1 || =140.5.0esr-1~deb12u1 || =140.5.0esr-1~deb13u1 || =140.6.0esr-1 || =140.6.0esr-1~deb11u1 || =140.6.0esr-1~deb12u1 || =140.6.0esr-1~deb13u1 || =140.7.0esr-1 || =140.7.0esr-1~deb11u1 || =140.7.0esr-1~deb12u1 || =140.7.0esr-1~deb13u1 || =140.8.0esr-1 || =140.8.0esr-1~deb11u1 || =140.8.0esr-1~deb12u1 || =140.8.0esr-1~deb13u1 || =78.12.0esr-1 || =78.13.0esr-1 || =78.13.0esr-1~deb10u1 || =78.13.0esr-1~deb11u1 || =78.13.0esr-1~deb9u1 || =78.14.0esr-1 || =78.14.0esr-1~deb10u1 || =78.14.0esr-1~deb11u1 || =78.14.0esr-1~deb9u1 || =78.15.0esr-1~deb10u1 || =78.15.0esr-1~deb11u1 || =78.15.0esr-1~deb9u1 || =91.0.1esr-1 || =91.0esr-1 || =91.1.0esr-1 || =91.10.0esr-1 || =91.10.0esr-1~deb10u1 || =91.10.0esr-1~deb11u1 || =91.10.0esr-1~deb9u1 || =91.11.0esr-1 || =91.11.0esr-1~deb10u1 || =91.11.0esr-1~deb11u1 || =91.11.0esr-1~deb9u1 || =91.12.0esr-1 || =91.12.0esr-1~deb10u1 || =91.12.0esr-1~deb11u1 || =91.13.0esr-1~deb10u1 || =91.13.0esr-1~deb11u1 || =91.2.0esr-1 || =91.3.0esr-1 || =91.3.0esr-2 || =91.4.0esr-1 || =91.4.1esr-1~deb11u1 || =91.4.1esr-1~deb9u1 || =91.5.0esr-1 || =91.5.0esr-1~deb10u1 || =91.5.0esr-1~deb11u1 || =91.5.0esr-1~deb9u1 || =91.5.1esr-1 || =91.6.0esr-1 || =91.6.0esr-1~deb10u1 || =91.6.0esr-1~deb11u1 || =91.6.0esr-1~deb9u1 || =91.6.1esr-1 || =91.6.1esr-1~deb10u1 || =91.6.1esr-1~deb11u1 || =91.6.1esr-1~deb9u1 || =91.7.0esr-1 || =91.7.0esr-1~deb10u1 || =91.7.0esr-1~deb11u1 || =91.7.0esr-1~deb9u1 || =91.8.0esr-1 || =91.8.0esr-1~deb10u1 || =91.8.0esr-1~deb11u1 || =91.8.0esr-1~deb9u1 || =91.9.0esr-1 || =91.9.0esr-1~deb10u1 || =91.9.0esr-1~deb11u1 || =91.9.0esr-1~deb9u1 || =91.9.1esr-1 || =91.9.1esr-1~deb10u1 || =91.9.1esr-1~deb11u1 || =91.9.1esr-1~deb9u1 || >=0 <140.9.0esr-1~deb11u1 | 140.9.0esr-1~deb11u1 |
1-10 of 27
10
Does your application use this vulnerable software?
During the free trial, our tools assess your application, identify vulnerabilities, and provide recommendations for their remediation.