CVE-2023-5168
Summary
| CVE | CVE-2023-5168 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-09-27 15:19:00 UTC |
| Updated | 2023-10-10 15:15:00 UTC |
| Description | A compromised content process could have provided malicious data to `FilterNodeD2D1` resulting in an out-of-bounds write, leading to a potentially exploitable crash in a privileged process.
*This bug only affects Firefox on Windows. Other operating systems are unaffected.* This vulnerability affects Firefox < 118, Firefox ESR < 115.3, and Thunderbird < 115.3. |
NVD Known Affected Configurations (CPE 2.3)
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 296106 Oracle Solaris 11.4 Support Repository Update (SRU) 64.157.2 Missing (CPUOCT2023)
- 356892 Amazon Linux Security Advisory for firefox : ALAS2FIREFOX-2023-017
- 378899 Mozilla Firefox ESR Multiple Vulnerabilities (MFSA2023-42)
- 378900 Mozilla Firefox Multiple Vulnerabilities (MFSA2023-41)
- 378901 Mozilla Thunderbird Multiple Vulnerabilities (MFSA2023-43)
- 503462 Alpine Linux Security Update for firefox-esr
- 506070 Alpine Linux Security Update for firefox-esr
- 710875 Gentoo Linux Mozilla Thunderbird Multiple Vulnerabilities (GLSA 202402-25)
- 754953 SUSE Enterprise Linux Security Update for MozillaFirefox (SUSE-SU-2023:3837-1)
- 754994 SUSE Enterprise Linux Security Update for MozillaFirefox (SUSE-SU-2023:3899-1)
- 754995 SUSE Enterprise Linux Security Update for MozillaFirefox (SUSE-SU-2023:3898-1)
- 755053 SUSE Enterprise Linux Security Update for MozillaThunderbird (SUSE-SU-2023:4016-1)