Seeing an issue where the Mozilla Maintenance Service is showing up for many Windows endpoints with the wrong version. Because of this, many vulnerabilities are being reported that don’t seem to exist.
Vulnerability being reported:

Package version information from the device’s LC sensor:
Thanks for the report. Taking a look.
Could you trigger a rescan of that host for packages? I think there may be two different issues at the play, and one of them is simply version lag. The end points are scanned once a day, so it’s not impossible for you to see a vulnerability reported, but the sensor reporting a newer version if it has been patched in between the two times.
That seems to have been the case. After triggering another scan the versions match. But, now I am seeing this:
154.0.1 is the latest version but now Vulnerability Reporting is showing a 10 year old CVE? This would seem to be a false positive, right?