Impact
The flaw involves incorrect boundary checks in the editor component’s DOM handling, which can lead to memory corruption or application instability when malformed input is processed. The vulnerability is not conducive to remote code execution but can cause the program to crash or become unresponsive, thereby denying service to legitimate users. The weakness is a classic example of improper input bounds validation (CWE-129).
Affected Systems
Mozilla Firefox, including the ESR 153.3 branch, and Mozilla Thunderbird are affected. The documented fix appears in Firefox 156, Firefox ESR 153.3, and Thunderbird 156. All earlier releases lack the boundary‑validation patch and remain vulnerable.
Risk and Exploitability
No EPSS score is available and the vulnerability is not listed in the CISA KEV catalog, which suggests that active exploitation has not been observed. However, the nature of the flaw—memory corruption triggered by crafted content—implies a high potential for denial of service if an attacker can supply malicious files or web pages to the editor. The absence of a disclosed CVSS score does not diminish the severity of a crash scenario, and users should consider the risk moderate to high until the patch is applied.
OpenCVE Enrichment