Description
Incorrect boundary conditions in the Audio/Video: Playback component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17.
Published: 2026-09-29
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service via memory corruption
Action: Immediate Patch
AI Analysis

Impact

Incorrect boundary conditions were identified in the audio/video playback component of Mozilla Firefox. The flaw allows the browser to read or write outside the intended memory bounds when decoding media files, which can cause the application to crash or exhibit erratic behavior. The primary consequence is a denial of service, as affected users may experience disruption or termination of media playback. While memory corruption could theoretically be escalated, the vulnerability description does not confirm arbitrary code execution.

Affected Systems

The vulnerability is present in all Mozilla Firefox releases older than Firefox ESR 115.42, Firefox ESR 140.17, Firefox ESR 153.4, and the standard release Firefox 157. Users on earlier builds remain vulnerable until they upgrade to any of the patched releases mentioned.

Risk and Exploitability

The issue is not listed in CISA’s KEV catalog and no exploit has been published, indicating a low or moderate risk footprint. The EPSS score is not available, leaving the likelihood of exploitation uncertain. Based on the description, it is inferred that the bug can be triggered by playing a malformed media file, meaning the likely attack vector involves a user opening or streaming such content. Exploitation would require the attacker to supply specialized media to the victim or host it via a web page that forces playback. Although memory corruption opens the possibility of remote code execution, achieving that outcome would almost certainly need additional techniques beyond the boundary error itself.

Generated by OpenCVE AI on September 30, 2026 at 06:58 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update to Mozilla Firefox ESR 153.4 or later, or the standard release Firefox 157
  • Enable automatic updates to receive future security patches promptly
  • Monitor Mozilla security advisories for related updates and stay informed of further mitigation steps

Generated by OpenCVE AI on September 30, 2026 at 06:58 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 30 Sep 2026 04:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-119
CWE-120

Tue, 29 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
First Time appeared Mozilla
Mozilla firefox
Vendors & Products Mozilla
Mozilla firefox

Tue, 29 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-119
CWE-120

Tue, 29 Sep 2026 13:15:00 +0000

Type Values Removed Values Added
Description Incorrect boundary conditions in the Audio/Video: Playback component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17.
Title Incorrect boundary conditions in the Audio/Video: Playback component
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mozilla

Published:

Updated: 2026-09-29T12:35:52.765Z

Reserved: 2026-09-26T19:15:13.788Z

Link: CVE-2026-100756

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-29T13:17:39.950

Modified: 2026-09-29T21:27:41.130

Link: CVE-2026-100756

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-30T07:00:15Z

Weaknesses

No weakness.