CVE-2023-25752
Last modified
CVE-2023-25752 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. When accessing throttled streams, the count of available bytes needed to be checked in the calling function to be within bounds. This may have lead future code to be incorrect and vulnerable. EPSS estimates a 0.61% chance of exploitation in the next 30 days.
Description
When accessing throttled streams, the count of available bytes needed to be checked in the calling function to be within bounds. This may have lead future code to be incorrect and vulnerable. This vulnerability affects Firefox < 111, Firefox ESR < 102.9, and Thunderbird < 102.9.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Mozilla | Firefox | < 111.0 |
| Mozilla | Firefox Esr | < 102.9 |
| Mozilla | Thunderbird | < 102.9 |
References
- https://bugzilla.mozilla.org/show_bug.cgi?id=1811627Issue Tracking, Permissions Required, Vendor Advisory
- https://www.mozilla.org/security/advisories/mfsa2023-09/Vendor Advisory
- https://www.mozilla.org/security/advisories/mfsa2023-10/Vendor Advisory
- https://www.mozilla.org/security/advisories/mfsa2023-11/Vendor Advisory
- https://bugzilla.mozilla.org/show_bug.cgi?id=1811627Issue Tracking, Permissions Required, Vendor Advisory
- https://www.mozilla.org/security/advisories/mfsa2023-09/Vendor Advisory
- https://www.mozilla.org/security/advisories/mfsa2023-10/Vendor Advisory
- https://www.mozilla.org/security/advisories/mfsa2023-11/Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2023-25752?
How severe is CVE-2023-25752?
How do I fix CVE-2023-25752?
Are you affected by CVE-2023-25752?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
