Back

HIGH

Mozilla: Undefined behavior in <code>ShutdownObserver()</code>

Published Dec 19, 2023

Description

The `ShutdownObserver()` was susceptible to potentially undefined behavior due to its reliance on a dynamic type that lacked a virtual destructor. This vulnerability affects Firefox ESR < 115.6, Thunderbird < 115.6, and Firefox < 121.

Affected products

Remediation

Red Hat statement

Red Hat Product Security rates the severity of this flaw as determined by the Mozilla Foundation Security Advisory.

References (14)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mozilla
Published Dec 19, 2023
Updated Feb 13, 2025
Reserved Dec 15, 2023
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Low
Public date Dec 19, 2023
ENISA EUVD
Assigner mozilla
Published Dec 19, 2023
Updated Feb 13, 2025
Exploited since n/a
EUVD-2023-59067