- Description
 - Parsing a JavaScript module as JSON could, under some circumstances, cause cross-compartment access, which may result in a use-after-free. This vulnerability affects Firefox < 134, Firefox ESR < 128.6, Thunderbird < 134, and Thunderbird < 128.6.
 - Source
 - security@mozilla.org
 - NVD status
 - Modified
 - Products
 - firefox, thunderbird
 
CVSS 3.1
- Type
 - Secondary
 - Base score
 - 4
 - Impact score
 - 1.4
 - Exploitability score
 - 2.5
 - Vector string
 - CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
 - Severity
 - MEDIUM
 
- 134c704f-9b21-4f2e-91b3-4a467353bcc0
 - CWE-416
 
- Hype score
 - Not currently trending
 
[
  {
    "nodes": [
      {
        "negate": false,
        "cpeMatch": [
          {
            "criteria": "cpe:2.3:a:mozilla:firefox:*:*:*:*:esr:*:*:*",
            "vulnerable": true,
            "matchCriteriaId": "AEBB7F43-496D-4A67-8E9E-EEE29913B6DE",
            "versionEndExcluding": "128.6.0"
          },
          {
            "criteria": "cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*",
            "vulnerable": true,
            "matchCriteriaId": "4FDCA935-A68D-404E-A749-CA3845C709F0",
            "versionEndExcluding": "134.0"
          },
          {
            "criteria": "cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*",
            "vulnerable": true,
            "matchCriteriaId": "C92D62DE-A681-4B9D-9640-D12D04392A1B",
            "versionEndExcluding": "128.6.0"
          },
          {
            "criteria": "cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*",
            "vulnerable": true,
            "matchCriteriaId": "A633E231-80F8-4A92-BA69-B9BE5BE45D00",
            "versionEndExcluding": "134.0",
            "versionStartIncluding": "129.0"
          }
        ],
        "operator": "OR"
      }
    ]
  }
]