Impact
The vulnerability is caused by incorrect boundary checks in the network component, which could lead to undefined behavior when processing malformed packets. This flaw is classified as CWE‑120 and may result in an application crash or denial of service. The description does not state that it allows arbitrary code execution; the impact is limited to instability or availability loss.
Affected Systems
Mozilla Firefox versions older than 156 (or older than ESR 153.3) and Mozilla Thunderbird versions older than 156 (or older than 153.3) are affected.
Risk and Exploitability
The CVSS score is 8.8, indicating high severity. The EPSS score of < 1% reflects a very low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. Since the flaw resides in the networking stack, an attacker would need to send crafted network traffic to the vulnerable application, which is the primary inferred attack vector.
OpenCVE Enrichment