Impact
An integer overflow exists in the Audio/Video component of Mozilla browsers and email client. The flaw can cause memory corruption or application failure when processing malformed media data, thereby potentially compromising application integrity.
Affected Systems
The vulnerability affects Mozilla Firefox versions 148 and later, as well as Firefox ESR 115.33 and ESR 140.8, and Mozilla Thunderbird versions 148 and later, including Thunderbird ESR 140.8.
Risk and Exploitability
A high‑severity risk is indicated by a score of 8.8, while the exploitation probability is very low (<1%). It is not listed in CISA’s KEV catalog. The likely attack vector involves an attacker supplying a malicious audio or video file that triggers the overflow during media decoding, which could result in memory corruption exploitable for code execution or denial of service.
OpenCVE Enrichment
Debian DLA
Debian DSA