Impact
The vulnerability is caused by incorrect boundary checks within the graphics subsystem, which can lead to memory corruption and potentially allow an attacker to execute arbitrary code. This flaw is classified as CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer. Mozilla Firefox 153 and Mozilla Firefox ESR 115.38/140.13, as well as Mozilla Thunderbird 153 and Mozilla Thunderbird ESR 140.13, are vulnerable, indicating that earlier releases remain at risk.
Affected Systems
The affected products are Mozilla Firefox and Mozilla Thunderbird. Versions prior to Firefox 153, as well as Firefox ESR 115.38 and 140.13, are impacted, along with corresponding Thunderbird releases before version 153 or the ESR 140.13 release.
Risk and Exploitability
The CVSS score of 9.8 and the EPSS score of less than 1% indicate that exploitation attempts are expected to be rare at this time. The issue is not listed in the CISA KEV catalog. The most likely attack vector involves an attacker loading malicious content that triggers graphics operations, such as a crafted image or vector graphic, which could lead to arbitrary code execution on the affected system.
OpenCVE Enrichment
Debian DLA
Debian DSA