Impact
An invalid pointer dereference in the DOM Bindings (WebIDL) component can lead to memory corruption, potentially causing application crashes or denial of service. The weakness arises from improper memory pointer handling, corresponding to the listed CWE identifiers.
Affected Systems
Mozilla Firefox and Mozilla Thunderbird are affected. The CVE text specifies the flaw was fixed starting with Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13, implying versions prior to those are affected. This is inferred from the fix information; the original data does not list all vulnerable revisions.
Risk and Exploitability
The CVSS score of 9.8 indicates critical severity. The EPSS score of <1% means the current exploitation probability is very low. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector involves malicious web content that exploits the faulty WebIDL component; this inference is based on the nature of the component and is not explicitly stated in the data.
OpenCVE Enrichment
Debian DLA
Debian DSA