Impact
The vulnerability arises from incorrect handling of boundary conditions in the Audio/Video playback component, leading to memory corruption that can enable an attacker to execute arbitrary code or cause a crash. It is classified under CWE‑754 and CWE‑823 and carries a CVSS score of 7.5, indicating a high potential impact on confidentiality, integrity, and availability.
Affected Systems
The issue affects Mozilla Firefox versions before 149 (including ESR releases 115.34 and 140.9) and Mozilla Thunderbird versions before 149 (including ESR 140.9).
Risk and Exploitability
The EPSS score is below 1 % and the vulnerability is not listed in the CISA KEV catalog, suggesting a low likelihood of exploitation. The attack vector is believed to be attainable via crafted media files processed by the affected browsers, potentially allowing remote code execution if an attacker can obtain execution control over the playback component. In the absence of a confirmed exploit, the main risk remains the possibility of denial‑of‑service or information disclosure through the corrupted memory state.
OpenCVE Enrichment
Debian DLA
Debian DSA