Description
Uninitialized memory in the Audio/Video component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17.
Published: 2026-09-29
Score: 4.3 Medium
EPSS: n/a
KEV: No
Impact: Information Disclosure
Action: Apply Patch
AI Analysis

Impact

An uninitialized memory condition in the browser’s Audio/Video component can lead to the component reading data that has not been set by the application, which may expose unintended user data or cause the browser to crash or behave unpredictably. The description does not state a confirmed exploitation path, but the undefined behavior could affect confidentiality and stability.

Affected Systems

The issue affects Mozilla Firefox versions that precede the fixes listed in the advisory. The vulnerability was resolved in Firefox ESR 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17, so any build older than these releases is potentially vulnerable.

Risk and Exploitability

EPSS information is not available and the vulnerability is not listed in the CISA KEV catalog, indicating there is no known widespread exploitation. No CVSS score is provided, so the exact severity cannot be quantified. Based on the nature of the flaw, the likely attack vector would involve a malicious or malformed media file or a web page that triggers the Audio/Video component, however this inference is drawn from the description rather than explicit data. The risk remains uncertain but could lead to information leakage or application instability if triggered successfully.

Generated by OpenCVE AI on September 29, 2026 at 16:40 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Firefox to a version that includes the fix—ESR 153.4 or newer, Firefox 157 or newer, or the corresponding ESR 115.42/140.17 releases.
  • If an upgrade is not immediately possible, restrict or disable the use of the Audio/Video component via browser policies or extensions to reduce the attack surface.
  • Regularly monitor Mozilla’s security advisories for additional patches and apply them promptly once available.

Generated by OpenCVE AI on September 29, 2026 at 16:40 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 29 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-457
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 29 Sep 2026 17:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-788

Tue, 29 Sep 2026 16:45:00 +0000

Type Values Removed Values Added
First Time appeared Mozilla
Mozilla firefox
Vendors & Products Mozilla
Mozilla firefox

Tue, 29 Sep 2026 13:15:00 +0000

Type Values Removed Values Added
Description Uninitialized memory in the Audio/Video component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17.
Title Uninitialized memory in the Audio/Video component
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mozilla

Published:

Updated: 2026-09-29T16:30:01.160Z

Reserved: 2026-09-26T19:17:00.731Z

Link: CVE-2026-100783

cve-icon Vulnrichment

Updated: 2026-09-29T16:27:08.648Z

cve-icon NVD

Status : Received

Published: 2026-09-29T13:17:43.247

Modified: 2026-09-29T17:17:03.807

Link: CVE-2026-100783

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-29T16:45:17Z

Weaknesses
  • CWE-457

    Use of Uninitialized Variable

  • CWE-788

    Access of Memory Location After End of Buffer