Impact
Incorrect boundary conditions in the Graphics: Canvas2D component allow an attacker to supply malformed graphics data that causes the rendering engine to write outside the bounds of a buffer, leading to a crash. The resulting denial of service compromises availability of the affected application for the user.
Affected Systems
Mozilla Firefox and Mozilla Thunderbird are affected. Vulnerable versions include all releases prior to Firefox 149 and ESR 115.34 (and ESR 140.9) as well as Thunderbird 149 and Thunderbird 140.9. Any instance running these versions could be impacted.
Risk and Exploitability
The CVSS base score of 7.5 classifies the flaw as high. With an EPSS score below 1 % the likelihood of exploitation is low and the vulnerability is not currently listed in the CISA KEV catalog. The defect requires that the attacker be able to trick the rendering engine into processing crafted graphics data, which is typically achieved by displaying a malicious web page or mail. Thus the attack vector is likely a local or remote content that exploits the rendering engine.
OpenCVE Enrichment
Debian DLA
Debian DSA