CVE-2023-25752
Last modified
CVE-2023-25752 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. When accessing throttled streams, the count of available bytes needed to be checked in the calling function to be within bounds. This may have lead future code to be incorrect and vulnerable. EPSS estimates a 0.61% chance of exploitation in the next 30 days.
Description
When accessing throttled streams, the count of available bytes needed to be checked in the calling function to be within bounds. This may have lead future code to be incorrect and vulnerable. This vulnerability affects Firefox < 111, Firefox ESR < 102.9, and Thunderbird < 102.9.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Mozilla | Firefox | < 111.0 |
| Mozilla | Firefox Esr | < 102.9 |
| Mozilla | Thunderbird | < 102.9 |
References
- https://bugzilla.mozilla.org/show_bug.cgi?id=1811627Issue Tracking, Permissions Required, Vendor Advisory
- https://www.mozilla.org/security/advisories/mfsa2023-09/Vendor Advisory
- https://www.mozilla.org/security/advisories/mfsa2023-10/Vendor Advisory
- https://www.mozilla.org/security/advisories/mfsa2023-11/Vendor Advisory
- https://bugzilla.mozilla.org/show_bug.cgi?id=1811627Issue Tracking, Permissions Required, Vendor Advisory
- https://www.mozilla.org/security/advisories/mfsa2023-09/Vendor Advisory
- https://www.mozilla.org/security/advisories/mfsa2023-10/Vendor Advisory
- https://www.mozilla.org/security/advisories/mfsa2023-11/Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2023-25752?
How severe is CVE-2023-25752?
How do I fix CVE-2023-25752?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2023
- CVE-2023-25747A potential use-after-free in libaudio was fixed by disablin…7.5
- CVE-2023-25748By displaying a prompt with a long description, the fullscre…4.3
- CVE-2023-25749Android applications with unpatched vulnerabilities can be l…4.3
- CVE-2023-2575Advantech EKI-1524, EKI-1522, EKI-1521 devices through 1.21 …8.8
- CVE-2023-25750Under certain circumstances, a ServiceWorker's offline cache…4.3
- CVE-2023-25751Sometimes, when invalidating JIT code while following an ite…6.5
- CVE-2023-25753 There exists an SSRF (Server-Side Request Forgery) vulnerab…6.5
- CVE-2023-25754Privilege Context Switching Error vulnerability in Apache So…9.8
- CVE-2023-25755Screen Creator Advance 2 Ver.0.1.1.4 Build01A and earlier is…7.8
- CVE-2023-25756Out-of-bounds read in the BIOS firmware for some Intel(R) Pr…8
- CVE-2023-25757Improper access control in some Intel(R) Unison(TM) software…7.2
- CVE-2023-25758Onekey Touch devices through 4.0.0 and Onekey Mini devices t…4.2
Are you affected by CVE-2023-25752?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
