Impact
This vulnerability involves incorrect boundary checks in the Canvas2D graphics component, potentially allowing out‑of‑bounds memory reads or writes. The resulting memory corruption can cause stability issues or other unintended behavior within Firefox or Thunderbird.
Affected Systems
Mozilla Firefox and Thunderbird, including the extended support releases. All versions prior to Firefox 149, Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9 are affected.
Risk and Exploitability
The CVSS base score of 7.5 indicates high severity. The EPSS score is below 1 %, implying low exploitation likelihood so far. The vulnerability is not listed in the CISA KEV catalog. The description does not specify an attack vector; it is inferred that malicious web content or media that feeds into the Canvas2D component could potentially trigger the flaw.
OpenCVE Enrichment
Debian DLA
Debian DSA