HIGH
Memory safety bugs present in Firefox 120
Published Dec 19, 2023
8.8
HIGHCVSS 3.1
EPSS 0.85%
Description
Memory safety bugs present in Firefox 120. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 121.
Affected products
-
Affected
- ≥ unspecified, < 121
Configuration 2
OR
- 10.0
- 11.0
- 12.0
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (6)
- https://bugzilla.mozilla.org/buglist.cgi?bug_id=1855327%2C1862089%2C1862723 Broken LinkIssue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-59077 Advisory
- https://lists.debian.org/debian-lts-announce/2023/12/msg00021.html Mailing ListThird Party Advisory
- https://security.gentoo.org/glsa/202401-10 Third Party Advisory
- https://www.debian.org/security/2023/dsa-5582 Third Party Advisory
- https://www.mozilla.org/security/advisories/mfsa2023-56/ Vendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://bugzilla.mozilla.org/buglist.cgi?bug_id=1855327%2C1862089%2C1862723 | Broken LinkIssue Tracking | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-59077 | Advisory | |
| https://lists.debian.org/debian-lts-announce/2023/12/msg00021.html | Mailing ListThird Party Advisory | |
| https://security.gentoo.org/glsa/202401-10 | Third Party Advisory | |
| https://www.debian.org/security/2023/dsa-5582 | Third Party Advisory | |
| https://www.mozilla.org/security/advisories/mfsa2023-56/ | Vendor Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mozilla
Published Dec 19, 2023
Updated Feb 13, 2025
Reserved Dec 15, 2023
Link CVE-2023-6873
CISA Vulnrichment
No data
Red Hat
No data
GitHub
No data