8.6

CVE-2023-4576

Integer Overflow in RecordedSourceSurfaceCreation

On Windows, an integer overflow could occur in `RecordedSourceSurfaceCreation` which resulted in a heap buffer overflow potentially leaking sensitive data that could have led to a sandbox escape.
*This bug only affects Firefox on Windows. Other operating systems are unaffected.* This vulnerability affects Firefox < 117, Firefox ESR < 102.15, Firefox ESR < 115.2, Thunderbird < 102.15, and Thunderbird < 115.2.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Mozilla ≫ Firefox Version < 117.0
   Microsoft ≫ Windows Version -
Mozilla ≫ Firefox Version >= 115.0 < 115.2
   Microsoft ≫ Windows Version -
Mozilla ≫ Firefox ESR Version < 102.15
   Microsoft ≫ Windows Version -
Mozilla ≫ Thunderbird Version < 115.2
   Microsoft ≫ Windows Version -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.69% 0.478
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 8.6 3.9 4
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
CWE-190 Integer Overflow or Wraparound

The product performs a calculation that can produce an integer overflow or wraparound when the logic assumes that the resulting value will always be larger than the original value. This occurs when an integer value is incremented to a value that is too large to store in the associated representation. When this occurs, the value may become a very small or negative number.

https://www.mozilla.org/security/advisories/mfsa2023-36/
Vendor Advisory
https://www.mozilla.org/security/advisories/mfsa2023-38/
Vendor Advisory
https://www.mozilla.org/security/advisories/mfsa2023-34/
Vendor Advisory
https://www.mozilla.org/security/advisories/mfsa2023-35/
Vendor Advisory
https://www.mozilla.org/security/advisories/mfsa2023-37/
https://bugzilla.mozilla.org/show_bug.cgi?id=1846694
Issue Tracking
Permissions Required