Impact
The flaw involves incorrect boundary checks in the editor component’s DOM handling, which can lead to memory corruption or application instability when malformed input is processed. The vulnerability is not conducive to remote code execution but can cause the program to crash or become unresponsive, thereby denying service to legitimate users. The weakness is a classic example of improper memory management (CWE-787) and improper bounds checking (CWE-119).
Affected Systems
Mozilla Firefox, including the ESR 153.3 branch, and Mozilla Thunderbird are affected. The documented fix appears in Firefox 156, Firefox ESR 153.3, and Thunderbird 156. All earlier releases lack the boundary‑validation patch and remain vulnerable.
Risk and Exploitability
EPSS score < 1% and the vulnerability is not listed in the CISA KEV catalog, which suggests that active exploitation has not been observed. However, the nature of the flaw—memory corruption triggered by crafted content—implies a high potential for denial of service if an attacker can supply malicious files or web pages to the editor. The CVSS score of 9.3 indicates high severity, so the risk remains high until the patch is applied.
OpenCVE Enrichment