Impact
A flaw in the security component can cause the application to crash or become unresponsive, leading to a denial of service for the user. An attacker could trigger this by delivering malicious content or otherwise interacting with the compromised component, resulting in component failure without compromising confidentiality or integrity.
Affected Systems
Mozilla Firefox versions up to 156 and Firefox ESR 153.3, as well as Mozilla Thunderbird up to and including 156, are affected. These versions include the vulnerable security component and must be updated to a fixed release.
Risk and Exploitability
The vulnerability is not listed in the CISA KEV catalog, and the EPSS score is 0.00144 (<1%), indicating a very low probability of exploitation. Nevertheless, the vulnerability permits service disruption, potentially impacting users in a wide range of environments. The likely attack vector inferred from the description is a remote trigger by a malicious web page or message that engages the security component, as the flaw resides within part of the application that processes external content.
OpenCVE Enrichment