CVE-2023-37212Out-of-bounds Write in Mozilla Firefox

Severity
8.8HIGHNVD
OSV6.5
EPSS
0.3%
top 45.73%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 5

Description

Memory safety bugs present in Firefox 114. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 115.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages5 packages

debiandebian/firefox< firefox 115.0-1 (sid)
CVEListV5mozilla/firefoxunspecified115
NVDmozilla/firefox< 115.0
Ubuntumozilla/firefox< 115.0+build2-0ubuntu0.20.04.3
mozillamozilla/firefox

🔴Vulnerability Details

3
OSV
firefox vulnerabilities2023-07-05
GHSA
GHSA-g84x-frx3-v352: Memory safety bugs present in Firefox 1142023-07-05
OSV
CVE-2023-37212: Memory safety bugs present in Firefox 1142023-07-05

📋Vendor Advisories

3
Ubuntu
Firefox vulnerabilities2023-07-05
Debian
CVE-2023-37212: firefox - Memory safety bugs present in Firefox 114. Some of these bugs showed evidence of...2023
Mozilla
Mozilla Foundation Security Advisory 2023-22: CVE-2023-37212
CVE-2023-37212 — Out-of-bounds Write in Mozilla Firefox | cvebase