Impact
The flaw stems from incorrect boundary checks in the Networking: HTTP component of Mozilla products, leading to an unchecked memory write (CWE-787). This can corrupt adjacent memory, potentially causing a crash or other unstable behavior, but there is no evidence of remote code execution.
Affected Systems
Mozilla Firefox and Mozilla Thunderbird installations older than version 156 are affected; the issue was addressed in Firefox 156 and Thunderbird 156.
Risk and Exploitability
With a CVSS score of 9.8, the severity is critical, yet the EPSS score is below 1% and the vulnerability is not listed in CISA KEV, implying a low likelihood of exploitation. The effect is primarily a denial of service through application crashes, and based on the description, it is inferred that the attack vector is the delivery of malformed HTTP traffic over a network connection.
OpenCVE Enrichment