CVE-2023-4054
published 2023-08-01CVE-2023-4054: When opening appref-ms files, Firefox did not warn the user that these files may contain malicious code. *This bug only affects Firefox on Windows. Other…
PriorityP421medium5.5CVSS 3.1
AVLACLPRNUIRSUCNIHAN
EPSS
0.22%
12.5th percentile
When opening appref-ms files, Firefox did not warn the user that these files may contain malicious code.
*This bug only affects Firefox on Windows. Other operating systems are unaffected.* This vulnerability affects Firefox < 116, Firefox ESR < 102.14, Firefox ESR < 115.1, Thunderbird < 102.14, and Thunderbird < 115.1.
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | firefox | — | — |
| debian | firefox-esr | — | — |
| debian | thunderbird | — | — |
| juniper | junos_os | — | — |
| mozilla | firefox | < 116.0 | 116.0 |
| mozilla | firefox | — | — |
| mozilla | firefox | >= 102.0 < 102.14 | 102.14 |
| mozilla | firefox | >= 115.0 < 115.1 | 115.1 |
| mozilla | firefox | >= unspecified < 116 | 116 |
| mozilla | firefox_esr | >= unspecified < 102.14 | 102.14 |
| mozilla | firefox_esr | >= unspecified < 115.1 | 115.1 |
| mozilla | thunderbird | >= 0 < 1:102.15.0+build1-0ubuntu0.20.04.1 | 1:102.15.0+build1-0ubuntu0.20.04.1 |
| mozilla | thunderbird | >= 0 < 1:102.15.0+build1-0ubuntu0.22.04.1 | 1:102.15.0+build1-0ubuntu0.22.04.1 |
| mozilla | thunderbird | >= unspecified < 102.14 | 102.14 |
| mozilla | thunderbird | >= unspecified < 115.1 | 115.1 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
osv5.5MEDIUM
vendor_debian5.5LOW
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-ww29-fh6f-953x: When opening appref-ms files, Firefox did not warn the user that these files may contain malicious code
ghsa_unreviewed·2023-08-01
CVE-2023-4054 [MEDIUM] GHSA-ww29-fh6f-953x: When opening appref-ms files, Firefox did not warn the user that these files may contain malicious code
When opening appref-ms files, Firefox did not warn the user that these files may contain malicious code.
*This bug only affects Firefox on Windows. Other operating systems are unaffected.* This vulnerability affects Firefox < 116, Firefox ESR < 102.14, and Firefox ESR < 115.1.
OSV
CVE-2023-4054: When opening appref-ms files, Firefox did not warn the user that these files may contain malicious code
osv·2023-08-01·CVSS 5.5
CVE-2023-4054 [MEDIUM] CVE-2023-4054: When opening appref-ms files, Firefox did not warn the user that these files may contain malicious code
When opening appref-ms files, Firefox did not warn the user that these files may contain malicious code. *This bug only affects Firefox on Windows. Other operating systems are unaffected.* This vulnerability affects Firefox < 116, Firefox ESR < 102.14, Firefox ESR < 115.1, Thunderbird < 102.14, and Thunderbird < 115.1.
Red Hat
Mozilla: Lack of warning when opening appref-ms files
vendor_redhat·2023-08-01·CVSS 5.5
CVE-2023-4054 [MEDIUM] CWE-357 Mozilla: Lack of warning when opening appref-ms files
Mozilla: Lack of warning when opening appref-ms files
When opening appref-ms files, Firefox did not warn the user that these files may contain malicious code.
*This bug only affects Firefox on Windows. Other operating systems are unaffected.* This vulnerability affects Firefox < 116, Firefox ESR < 102.14, Firefox ESR < 115.1, Thunderbird < 102.14, and Thunderbird < 115.1.
A flaw was found in Mozilla. The Mozilla Foundation Security Advisory described this flaw when opening appref-ms files, Firefox did not warn the user that these files may contain malicious code. This bug only affects Firefox on Windows. Other operating systems are unaffected.
Statement: Red Hat Product Security rates the severity of this flaw as determined by the Mozilla Foundation Security Advisory.
Package: firefox
Juniper
CVE-2023-22396: An Uncontrolled Resource Consumption vulnerability in TCP processing on the Routing Engine (RE) of Juniper Networks Junos OS allows an unauthenticated
vendor_juniper·2023-01-13·CVSS 7.5
CVE-2023-22396 [HIGH] CWE-400 CVE-2023-22396: An Uncontrolled Resource Consumption vulnerability in TCP processing on the Routing Engine (RE) of Juniper Networks Junos OS allows an unauthenticated
CVE-2023-22396: An Uncontrolled Resource Consumption vulnerability in TCP processing on the Routing Engine (RE) of Juniper Networks Junos OS allows an unauthenticated network-based attacker to send crafted TCP packets destined to the device, resulting in an MBUF leak that ultimately leads to a Denial of Service (DoS). The system does not recover automatically and must be manually restarted to restore service. This issue occurs when crafted TCP packets are sent directly to a configured IPv4 or IPv6 interface on the device. Transit traffic will not trigger this issue. MBUF usage can be monitored through the use of the 'show system buffers' command. For example: user@junos> show system buffers | refresh 5 4054/566/4620 mbufs in use (current/cache/total) ... 4089/531/4620 mbufs in use (current
Debian
CVE-2023-4054: firefox - When opening appref-ms files, Firefox did not warn the user that these files may...
vendor_debian·2023·CVSS 5.5
CVE-2023-4054 [MEDIUM] CVE-2023-4054: firefox - When opening appref-ms files, Firefox did not warn the user that these files may...
When opening appref-ms files, Firefox did not warn the user that these files may contain malicious code. *This bug only affects Firefox on Windows. Other operating systems are unaffected.* This vulnerability affects Firefox < 116, Firefox ESR < 102.14, Firefox ESR < 115.1, Thunderbird < 102.14, and Thunderbird < 115.1.
Scope: local
sid: resolved
Mozilla
Mozilla Foundation Security Advisory 2023-33: CVE-2023-4054
vendor_mozilla·CVSS 5.5
CVE-2023-4054 [MEDIUM] Mozilla Foundation Security Advisory 2023-33: CVE-2023-4054
Mozilla Foundation Security Advisory 2023-33
CVE: CVE-2023-4054
Product: Thunderbird
Impact: high
Fixed in: Thunderbird 115.1
Mozilla
Mozilla Foundation Security Advisory 2023-29: CVE-2023-4054
vendor_mozilla·CVSS 5.5
CVE-2023-4054 [MEDIUM] Mozilla Foundation Security Advisory 2023-29: CVE-2023-4054
Mozilla Foundation Security Advisory 2023-29
CVE: CVE-2023-4054
Product: Firefox
Impact: high
Fixed in: Firefox 116
Mozilla
Mozilla Foundation Security Advisory 2023-30: CVE-2023-4054
vendor_mozilla·CVSS 5.5
CVE-2023-4054 [MEDIUM] Mozilla Foundation Security Advisory 2023-30: CVE-2023-4054
Mozilla Foundation Security Advisory 2023-30
CVE: CVE-2023-4054
Product: Firefox ESR
Impact: high
Fixed in: Firefox ESR 102.14
Mozilla
Mozilla Foundation Security Advisory 2023-31: CVE-2023-4054
vendor_mozilla·CVSS 5.5
CVE-2023-4054 [MEDIUM] Mozilla Foundation Security Advisory 2023-31: CVE-2023-4054
Mozilla Foundation Security Advisory 2023-31
CVE: CVE-2023-4054
Product: Firefox ESR
Impact: high
Fixed in: Firefox ESR 115.1
Mozilla
Mozilla Foundation Security Advisory 2023-32: CVE-2023-4054
vendor_mozilla·CVSS 5.5
CVE-2023-4054 [MEDIUM] Mozilla Foundation Security Advisory 2023-32: CVE-2023-4054
Mozilla Foundation Security Advisory 2023-32
CVE: CVE-2023-4054
Product: Thunderbird
Impact: high
Fixed in: Thunderbird 102.14
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://bugzilla.mozilla.org/show_bug.cgi?id=1840777https://www.mozilla.org/security/advisories/mfsa2023-29/https://www.mozilla.org/security/advisories/mfsa2023-30/https://www.mozilla.org/security/advisories/mfsa2023-31/https://www.mozilla.org/security/advisories/mfsa2023-32/https://www.mozilla.org/security/advisories/mfsa2023-33/https://bugzilla.mozilla.org/show_bug.cgi?id=1840777https://www.mozilla.org/security/advisories/mfsa2023-29/https://www.mozilla.org/security/advisories/mfsa2023-30/https://www.mozilla.org/security/advisories/mfsa2023-31/https://www.mozilla.org/security/advisories/mfsa2023-32/https://www.mozilla.org/security/advisories/mfsa2023-33/
2023-08-01
Published