Impact
The flaw is an integer overflow in Firefox’s Graphics: ImageLib component, caused when processing certain image data. The overflow can lead the browser to compute an incorrect size for a buffer and perform out‑of‑bounds memory writes or corruption, which may crash the application or, in some contexts, enable arbitrary code execution. This weakness is categorized as CWE‑680.
Affected Systems
Mozilla Firefox versions prior to 155 and Firefox ESR 153.2 are affected. All builds that include the Graphics: ImageLib component are vulnerable; the fix is included beginning with Firefox 155 and ESR 153.2.
Risk and Exploitability
No EPSS score is available and the vulnerability is not listed in the CISA KEV catalog, so public exploitation data is currently unknown. Attackers would need to supply a specially crafted image file that triggers the overflow, suggesting a local or remote exploitation scenario via web content or attachments. Because the flaw can cause denial of service or potentially allow code execution, the risk is considered high for systems running an affected version of Firefox.
OpenCVE Enrichment