CVE-2023-37456
published 2023-07-12CVE-2023-37456: The session restore helper crashed whenever there was no parameter sent to the message handler. This vulnerability affects Firefox for iOS < 115.
PriorityP426medium6.5CVSS 3.1
AVNACLPRNUIRSUCNINAH
EPSS
0.49%
38.7th percentile
The session restore helper crashed whenever there was no parameter sent to the message handler. This vulnerability affects Firefox for iOS < 115.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | firefox | — | — |
| mozilla | firefox | < 115 | 115 |
| mozilla | firefox | — | — |
| mozilla | firefox_for_ios | >= unspecified < 115 | 115 |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
vendor_debian6.5LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-rp8c-4xv6-27j8: The session restore helper crashed whenever there was no parameter sent to the message handler
ghsa_unreviewed·2023-07-12
CVE-2023-37456 [MEDIUM] CWE-476 GHSA-rp8c-4xv6-27j8: The session restore helper crashed whenever there was no parameter sent to the message handler
The session restore helper crashed whenever there was no parameter sent to the message handler. This vulnerability affects Firefox for iOS < 115.
Debian
CVE-2023-37456: firefox - The session restore helper crashed whenever there was no parameter sent to the m...
vendor_debian·2023·CVSS 6.5
CVE-2023-37456 [MEDIUM] CVE-2023-37456: firefox - The session restore helper crashed whenever there was no parameter sent to the m...
The session restore helper crashed whenever there was no parameter sent to the message handler. This vulnerability affects Firefox for iOS < 115.
Scope: local
sid: resolved
Mozilla
Mozilla Foundation Security Advisory 2023-25: CVE-2023-37456
vendor_mozilla·CVSS 6.5
CVE-2023-37456 [MEDIUM] Mozilla Foundation Security Advisory 2023-25: CVE-2023-37456
Mozilla Foundation Security Advisory 2023-25
CVE: CVE-2023-37456
Product: Firefox for iOS
Impact: low
Fixed in: Firefox for iOS 115
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2023-07-12
Published