Impact
The vulnerability is a denial‑of‑service in the audio/video component of Mozilla products. Attackers can cause the component to consume excessive resources, leading the application to crash or become unresponsive. This impact manifests as loss of service for users of Firefox or Thunderbird and can be triggered by supplying crafted media or by repeatedly initiating playback requests. The weakness involves uncontrolled resource consumption, corresponding to CWE‑400.
Affected Systems
The issue affects Mozilla Firefox and Mozilla Thunderbird. Versions prior to 156 are vulnerable. The fix was introduced in Firefox 156 and Thunderbird 156 and later releases.
Risk and Exploitability
The CVSS score is not provided, but the EPSS score is <1%, indicating a low exploitation probability. The vulnerability is not listed in the CISA KEV catalog, indicating no widespread known exploitation. Nevertheless, denial‑of‑service weaknesses can be abused either locally or via remote media streams if the application processes untrusted content. The likely attack vector is the handling of malicious media during playback or streaming, inferred from the description of the audio/video component. Monitoring for abnormal resource usage and service disruptions is recommended until a patch is applied.
OpenCVE Enrichment