Impact
An incorrect boundary condition in the Graphics component can trigger memory corruption when processing graphic data. This flaw allows an attacker to overwrite adjacent memory areas, which may lead to application crashes or, depending on the attack vector, the execution of arbitrary code. The vulnerability is categorized as CWE‑754 and CWE‑787, indicating buffer misuse that can corrupt heap or stack memory.
Affected Systems
Mozilla Firefox versions earlier than 149 and ESR 140.9, and Mozilla Thunderbird versions earlier than 149 and ESR 140.9 are affected by this flaw.
Risk and Exploitability
The CVSS score of 7.5 denotes a high severity. The EPSS score is below 1%, and the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector involves an attacker delivering a specially crafted graphic or attachment that forces the client to process the invalid boundary. This inference is based on the nature of the flaw and the affected product’s rendering responsibilities.
OpenCVE Enrichment
Debian DLA
Debian DSA