Mozilla · Thunderbird · CVE-2024-7527
**Name of the Vulnerable Software and Affected Versions**
Firefox versions prior to 129
Firefox ESR versions prior to 115.14
Firefox ESR versions prior to 128.1
Thunderbird versions prior to 128.1
Thunderbird versions prior to 115.14
**Description**
The issue is related to a use-after-free vulnerability in the Garbage Collector component of Mozilla browsers, including Firefox and Firefox ESR, as well as the Thunderbird email client. This could allow a remote attacker to execute arbitrary code by exploiting the vulnerability, which involves using memory after it has been freed.
**Recommendations**
For Firefox versions prior to 129, update to version 129 or later.
For Firefox ESR versions prior to 115.14, update to version 115.14 or later.
For Firefox ESR versions prior to 128.1, update to version 128.1 or later.
For Thunderbird versions prior to 128.1, update to version 128.1 or later.
For Thunderbird versions prior to 115.14, update to version 115.14 or later.