Impact
A denial‑of‑service flaw exists in the Widget component of Mozilla Firefox and Mozilla Thunderbird. The bug triggers uncontrolled resource consumption whenever the Widget process is invoked, which can lead to application unresponsiveness or crash. The impact is confined to the client‑side software and presents a high‑severity risk for users who depend on uninterrupted browser operation.
Affected Systems
All Mozilla Firefox releases prior to version 154, all Firefox ESR releases older than 153.1, all Mozilla Thunderbird releases earlier than 154, and all Thunderbird ESR releases older than 153.1 are affected. The fix is deployed starting with Firefox 154 / ESR 153.1 and Thunderbird 154 / ESR 153.1; all intermediate releases remain vulnerable.
Risk and Exploitability
The CVSS score of 7.5 indicates a high‑severity denial‑of‑service vulnerability, while the EPSS score of < 1% and absence from the CISA KEV catalog suggest a low probability of exploitation in the wild. The attack vector is not explicitly stated in the CVE description; it is inferred that an attacker would need to trigger the Widget component, possibly via locally privileged actions or by delivering content that causes the widget to load. No publicly disclosed exploit code is linked to this issue and the vulnerability remains unexploited at the time of analysis.
OpenCVE Enrichment