QID 378630
Date Published: 2023-07-05
QID 378630: Mozilla Firefox Multiple Vulnerabilities (MFSA2023-22)
Firefox is a free and open-source web browser developed for Windows, OS X, and Linux, with a mobile version for Android.
Mozilla Firefox is prone to
CVE-2023-3482: Block all cookies bypass for localstorage
CVE-2023-37201: Use-after-free in WebRTC certificate generation
CVE-2023-37202: Potential use-after-free from compartment mismatch in SpiderMonkey
CVE-2023-37203: Drag and Drop API may provide access to local system files
CVE-2023-37204: Fullscreen notification obscured via option element
CVE-2023-37205: URL spoofing in address bar using RTL characters
CVE-2023-37206: Insufficient validation of symlinks in the FileSystem API
CVE-2023-37207: Fullscreen notification obscured
CVE-2023-37208: Lack of warning when opening Diagcab files
CVE-2023-37209: Use-after-free in `NotifyOnHistoryReload`
CVE-2023-37210: Full-screen mode exit prevention
CVE-2023-37211: Memory safety bugs fixed in Firefox 115, Firefox ESR 102.13, and Thunderbird 102.13
CVE-2023-37212: Memory safety bugs fixed in Firefox 115
Affected Products:
Prior to Firefox 115
QID Detection Logic (Authenticated) :
This checks for vulnerable version of Firefox browser.
Note: The preceding description block is extracted directly from the security advisory. Using automation, we have attempted to clean and format it as much as possible without introducing additional issues.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
- MFSA2023-22 -
www.mozilla.org/en-US/security/advisories/mfsa2023-22/
CVEs related to QID 378630
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| MFSA2023-22 |
|