QID 379062

Date Published: 2023-11-27

QID 379062: Mozilla Firefox Multiple Vulnerabilities (MFSA2023-49)

Firefox is a free and open-source web browser developed by the Mozilla Foundation and its subsidiary for Windows, OS X, and Linux, with a mobile version for Android.

Mozilla Firefox is prone to
CVE-2023-6204: Out-of-bound memory access in WebGL2 blitFramebuffer
CVE-2023-6205: Use-after-free in MessagePort::Entangled
CVE-2023-6206: Clickjacking permission prompts using the fullscreen transition
CVE-2023-6207: Use-after-free in ReadableByteStreamQueueEntry::Buffer
CVE-2023-6208: Using Selection API would copy contents into X11 primary selection.
CVE-2023-6209: Incorrect parsing of relative URLs starting with "///"
CVE-2023-6210: Mixed-content resources not blocked in a javascript: pop-up
CVE-2023-6211: Clickjacking to load insecure pages in HTTPS-only mode
CVE-2023-6212: Memory safety bugs fixed in Firefox 120, Firefox ESR 115.5, and Thunderbird 115.5
CVE-2023-6213: Memory safety bugs fixed in Firefox 120
Affected Products:
Prior to Firefox 120

QID Detection Logic (Authenticated) :
This checks for vulnerable version of Firefox browser.

Successful exploitation of this vulnerability could lead to a security breach like evidence of memory corruption or could affect integrity, availability, and confidentiality.

  • CVSS V3 rated as Critical - 8.8 severity.
  • CVSS V2 rated as High - 6.4 severity.
  • Solution
    Vendor has released fix to address these vulnerabilities. Upgrade to Firefox 120 to fix vulnerability, you can also refer MFSA2023-49 or later for more details.
    Software Advisories
    Advisory ID Software Component Link
    MFSA2023-49 URL Logo www.mozilla.org/en-US/security/advisories/mfsa2023-49/