CVE-2023-25736Mozilla Firefox vulnerability

10 documents7 sources
Severity
9.8CRITICALNVD
OSV8.8
EPSS
0.5%
top 34.04%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 19

Description

An invalid downcast from `nsHTMLDocument` to `nsIContent` could have lead to undefined behavior. This vulnerability affects Firefox < 110.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages5 packages

debiandebian/firefox< firefox 110.0-1 (sid)
CVEListV5mozilla/firefoxunspecified110
NVDmozilla/firefox< 110.0
Ubuntumozilla/firefox< 110.0+build3-0ubuntu0.18.04.1+3
mozillamozilla/firefox

🔴Vulnerability Details

4
GHSA
GHSA-vg8c-w3pf-2vfh: An invalid downcast from `nsHTMLDocument` to `nsIContent` could have lead to undefined behavior2023-06-19
OSV
firefox regressions2023-03-01
OSV
firefox vulnerabilities2023-02-20
OSV
CVE-2023-25736: An invalid downcast from `nsHTMLDocument` to `nsIContent` could have lead to undefined behavior2023-02-15

📋Vendor Advisories

5
Ubuntu
Firefox regressions2023-03-01
Ubuntu
Firefox vulnerabilities2023-02-20
Red Hat
Mozilla: Invalid downcast in GetTableSelectionMode2023-02-14
Debian
CVE-2023-25736: firefox - An invalid downcast from `nsHTMLDocument` to `nsIContent` could have lead to und...2023
Mozilla
Mozilla Foundation Security Advisory 2023-05: CVE-2023-25736
CVE-2023-25736 — Mozilla Firefox vulnerability | cvebase