Impact
The flaw originates from incorrect handling of boundary conditions in the playback component that processes audio and video files. When a media file triggers an out‑of‑bounds memory access, the engine can crash, causing Firefox or Thunderbird to terminate unexpectedly. This results in a denial of service for the user but does not provide the attacker with any elevated privileges.
Affected Systems
Mozilla products with the affected release numbers are susceptible: Firefox versions older than 149, Firefox Extended Support Release versions older than 115.34 or 140.9, and Thunderbird versions older than 149 or 140.9. Users running any of these builds are at risk until they apply the newer releases.
Risk and Exploitability
The CVSS score of 7.5 classifies the issue as high severity, while the EPSS score of less than 1% indicates a low current exploitation probability. The vulnerability is not listed in the CISA KEV catalog. Attackers would have to entice a user to open or play a specially crafted audio or video file, such as via a malicious web page or email attachment, which represents a remote attack vector. The impact is limited to application availability and does not compromise confidentiality or integrity.
OpenCVE Enrichment
Debian DLA
Debian DSA