CVE-2023-5732
- EPSS 0.29%
- Veröffentlicht 25.10.2023 18:17:44
- Zuletzt bearbeitet 21.11.2024 08:42:22
An attacker could have created a malicious link using bidirectional characters to spoof the location in the address bar when visited. This vulnerability affects Firefox < 117, Firefox ESR < 115.4, and Thunderbird < 115.4.1.
CVE-2023-5721
- EPSS 0.28%
- Veröffentlicht 25.10.2023 18:17:43
- Zuletzt bearbeitet 21.11.2024 08:42:21
It was possible for certain browser prompts and dialogs to be activated or dismissed unintentionally by the user due to an insufficient activation-delay. This vulnerability affects Firefox < 119, Firefox ESR < 115.4, and Thunderbird < 115.4.1.
CVE-2023-5217
- EPSS 4.84%
- Veröffentlicht 28.09.2023 16:15:10
- Zuletzt bearbeitet 24.10.2025 14:07:24
Heap buffer overflow in vp8 encoding in libvpx in Google Chrome prior to 117.0.5938.132 and libvpx 1.13.1 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVE-2023-5168
- EPSS 0.26%
- Veröffentlicht 27.09.2023 15:19:42
- Zuletzt bearbeitet 01.05.2025 21:15:51
A compromised content process could have provided malicious data to `FilterNodeD2D1` resulting in an out-of-bounds write, leading to a potentially exploitable crash in a privileged process. *This bug only affects Firefox on Windows. Other operating s...
CVE-2023-5169
- EPSS 0.32%
- Veröffentlicht 27.09.2023 15:19:42
- Zuletzt bearbeitet 21.11.2024 08:41:13
A compromised content process could have provided malicious data in a `PathRecording` resulting in an out-of-bounds write, leading to a potentially exploitable crash in a privileged process. This vulnerability affects Firefox < 118, Firefox ESR < 115...
CVE-2023-5170
- EPSS 0.23%
- Veröffentlicht 27.09.2023 15:19:42
- Zuletzt bearbeitet 21.11.2024 08:41:13
In canvas rendering, a compromised content process could have caused a surface to change unexpectedly, leading to a memory leak of a privileged process. This memory leak could be used to effect a sandbox escape if the correct data was leaked. This vu...
CVE-2023-5171
- EPSS 0.32%
- Veröffentlicht 27.09.2023 15:19:42
- Zuletzt bearbeitet 21.11.2024 08:41:13
During Ion compilation, a Garbage Collection could have resulted in a use-after-free condition, allowing an attacker to write two NUL bytes, and cause a potentially exploitable crash. This vulnerability affects Firefox < 118, Firefox ESR < 115.3, and...
CVE-2023-5172
- EPSS 0.32%
- Veröffentlicht 27.09.2023 15:19:42
- Zuletzt bearbeitet 01.05.2025 18:15:52
A hashtable in the Ion Engine could have been mutated while there was a live interior reference, leading to a potential use-after-free and exploitable crash. This vulnerability affects Firefox < 118.
CVE-2023-5173
- EPSS 0.2%
- Veröffentlicht 27.09.2023 15:19:42
- Zuletzt bearbeitet 21.11.2024 08:41:13
In a non-standard configuration of Firefox, an integer overflow could have occurred based on network traffic (possibly under influence of a local unprivileged webpage), leading to an out-of-bounds write to privileged process memory. *This bug only a...
CVE-2023-5174
- EPSS 0.28%
- Veröffentlicht 27.09.2023 15:19:42
- Zuletzt bearbeitet 05.05.2025 15:15:53
If Windows failed to duplicate a handle during process creation, the sandbox code may have inadvertently freed a pointer twice, resulting in a use-after-free and a potentially exploitable crash. *This bug only affects Firefox on Windows when run in n...