Impact
Incorrect boundary checks in Mozilla Firefox’s Graphics: Text component create a buffer overflow (CWE‑119). This flaw could let an attacker corrupt memory, potentially causing crashes or other unintended behavior. Based on the description, it is inferred that if the overwritten data affects executable code or control flow, the impact could be more severe.
Affected Systems
All Mozilla Firefox users on operating systems running a version earlier than 151.0.3 are affected. The issue was fixed in Firefox 151.0.3, so versions 151.0.2 and below remain vulnerable.
Risk and Exploitability
The CVSS score of 7.5 signals high severity, while an EPSS score of < 1 % indicates a very low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog, and no public exploit has been documented, which keeps the overall risk moderate pending further evidence.
OpenCVE Enrichment