Impact
The vulnerability is an integer overflow caused by incorrect boundary checks in the Libraries component of NSS. The overflow can occur when NSS processes malformed input, potentially corrupting adjacent memory. An attacker who supplies crafted data could gain the ability to execute arbitrary code or trigger a denial of service, depending on the context. The weakness aligns with CWE‑190 and CWE‑787, which describe integer overflows and buffer overflows that may lead to uncontrolled memory behavior.
Affected Systems
Mozilla Firefox and Mozilla Thunderbird are affected. Versions released before 153 are vulnerable; Firefox 153 and Thunderbird 153 contain the fix.
Risk and Exploitability
The CVSS score of 9.8 indicates a high‑impact vulnerability with the potential for full arbitrary code execution. The EPSS score of less than 1% reflects a low probability of real‑world exploitation at this time, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that the attack vector is remote delivery of malformed data to NSS through network protocols exposed to NSS, or local delivery via user‑initiated actions that provide data to NSS.
OpenCVE Enrichment
Debian DLA
Debian DSA