Impact
This vulnerability is an integer overflow in the graphics component of Mozilla Firefox and Thunderbird. The CVE description does not specify the exact impact, but integer overflows can cause program crashes and potential denial‑of‑service conditions.
Affected Systems
All versions of Mozilla Firefox and Thunderbird released before the patched iterations are affected. Specifically, any Firefox product earlier than version 154, as well as Firefox ESR 140.14 and all versions earlier than 140.14, and any ESR 153.1 release earlier than 153.1, are vulnerable. Likewise, any Thunderbird product earlier than version 154, Thunderbird ESR 140.14 and earlier releases, and Thunderbird ESR 153.1 and earlier releases also carry the flaw.
Risk and Exploitability
The CVSS score of 9.8 signals critical severity. The EPSS score is less than 1% and the vulnerability is not listed in the CISA KEV catalog, but the potential for a crash still poses a significant availability risk. The likely attack vector is the delivery of crafted graphic content, such as an embedded image or attachment, which would trigger the overflow when processed. This inference is based on the nature of the integer overflow in the rendering engine.
OpenCVE Enrichment
Debian DLA
Debian DSA