Impact
This vulnerability is an integer overflow in the Graphics: ImageLib component that processes image data. The overflow can corrupt memory boundaries and may cause the application to crash, resulting in a denial of service or potentially affect the integrity of the program’s execution flow.
Affected Systems
Mozilla Firefox releases prior to version 155 and Firefox ESR 153.2, along with Mozilla Thunderbird releases prior to 155 and Thunderbird 153.2, are impacted. All builds containing the Graphics: ImageLib component are vulnerable until the relevant updates are applied.
Risk and Exploitability
The EPSS score of less than 1% indicates a very low probability of exploitation, and the vulnerability is not listed in CISA KEV, indicating no known public exploits at this time. The CVSS score of 9.8 reflects a severe risk. Based on the description, it is inferred that the attack vector involves a specially crafted image supplied through web content, email attachments, or other image-handling contexts, which can trigger the overflow. Though no active exploitation is reported, the potential for abrupt termination and possible compromise of program integrity places a high risk on systems running affected versions.
OpenCVE Enrichment