Impact
A malicious PDF file can trigger a crash in the PDF Viewer component of Mozilla Firefox and Thunderbird, resulting in the application terminating unexpectedly. The crash causes a denial of service that is local to the user’s session, blocking access to web content and potentially disrupting automated scripts or kiosk operations. The vulnerability is caused by insufficient resource handling and memory safety problems, identified as CWE‑400. Based on the description, it is inferred that the attacker must supply a carefully crafted PDF to trigger the crash; the vulnerable code does not perform adequate checks on input data and can be exploited via a supply‑of‑malformed PDF. The CVSS score of 7.5 reflects the local impact and the requirement for the victim to open the malicious PDF.
Affected Systems
All installations of Mozilla Firefox or Thunderbird older than version 155 are affected.
Risk and Exploitability
The EPSS score indicates a very low exploitation probability of less than 1 %, and the vulnerability is not listed in the CISA KEV catalog. The high CVSS score of 7.5 highlights the local denial‑of‑service risk when a user opens a malicious PDF. The attacker only needs to supply the crafted file; once processed, the PDF Viewer crashes, resulting in service disruption on the victim’s machine.
OpenCVE Enrichment