CVE-2023-37456NULL Pointer Dereference in Mozilla Firefox FOR IOS

Severity
6.5MEDIUMNVD
EPSS
0.4%
top 38.44%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 12

Description

The session restore helper crashed whenever there was no parameter sent to the message handler. This vulnerability affects Firefox for iOS < 115.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:HExploitability: 2.8 | Impact: 3.6

Affected Packages2 packages

NVDmozilla/firefox< 115
CVEListV5mozilla/firefox_for_iosunspecified115

🔴Vulnerability Details

2
GHSA
GHSA-rp8c-4xv6-27j8: The session restore helper crashed whenever there was no parameter sent to the message handler2023-07-12
CVEList
CVE-2023-37456: The session restore helper crashed whenever there was no parameter sent to the message handler2023-07-12

📋Vendor Advisories

2
Debian
CVE-2023-37456: firefox - The session restore helper crashed whenever there was no parameter sent to the m...2023
Mozilla
Mozilla Foundation Security Advisory 2023-25: CVE-2023-37456
CVE-2023-37456 — NULL Pointer Dereference in Mozilla | cvebase