Impact
Incorrect boundary conditions were identified in the audio/video playback component of Mozilla Firefox. The flaw allows the browser to read or write outside the intended memory bounds when decoding media files, which can cause the application to crash or exhibit erratic behavior. The primary consequence is a denial of service, as affected users may experience disruption or termination of media playback. While memory corruption could theoretically be escalated, the vulnerability description does not confirm arbitrary code execution.
Affected Systems
The vulnerability is present in all Mozilla Firefox releases older than Firefox ESR 115.42, Firefox ESR 140.17, Firefox ESR 153.4, and the standard release Firefox 157. Users on earlier builds remain vulnerable until they upgrade to any of the patched releases mentioned.
Risk and Exploitability
The issue is not listed in CISA’s KEV catalog and no exploit has been published, indicating a low or moderate risk footprint. The EPSS score is not available, leaving the likelihood of exploitation uncertain. Based on the description, it is inferred that the bug can be triggered by playing a malformed media file, meaning the likely attack vector involves a user opening or streaming such content. Exploitation would require the attacker to supply specialized media to the victim or host it via a web page that forces playback. Although memory corruption opens the possibility of remote code execution, achieving that outcome would almost certainly need additional techniques beyond the boundary error itself.
OpenCVE Enrichment