CVE-2023-37204
Last modified
CVE-2023-37204 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. A website could have obscured the fullscreen notification by using an option element by introducing lag via an expensive computational function. This could have led to user confusion and possible spoofing attacks. EPSS estimates a 0.43% chance of exploitation in the next 30 days.
Description
A website could have obscured the fullscreen notification by using an option element by introducing lag via an expensive computational function. This could have led to user confusion and possible spoofing attacks. This vulnerability affects Firefox < 115.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Mozilla | Firefox | < 115.0 |
References
- https://bugzilla.mozilla.org/show_bug.cgi?id=1832195Issue Tracking, Permissions Required
- https://www.mozilla.org/security/advisories/mfsa2023-22/Vendor Advisory
- https://bugzilla.mozilla.org/show_bug.cgi?id=1832195Issue Tracking, Permissions Required
- https://www.mozilla.org/security/advisories/mfsa2023-22/Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2023-37204?
How severe is CVE-2023-37204?
How do I fix CVE-2023-37204?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2023
- CVE-2023-37199 A CWE-94: Improper Control of Generation of Code ('Code Inj…7.2
- CVE-2023-3720The Upload Media By URL WordPress plugin before 1.0.8 does n…6.5
- CVE-2023-37200 A CWE-611: Improper Restriction of XML External Entity Refe…5.5
- CVE-2023-37201An attacker could have triggered a use-after-free condition …8.8
- CVE-2023-37202Cross-compartment wrappers wrapping a scripted proxy could h…8.8
- CVE-2023-37203Insufficient validation in the Drag and Drop API in conjunct…7.8
- CVE-2023-37205The use of RTL Arabic characters in the address bar may have…6.5
- CVE-2023-37206Uploading files which contain symlinks may have allowed an a…6.5
- CVE-2023-37207A website could have obscured the fullscreen notification by…6.5
- CVE-2023-37208When opening Diagcab files, Firefox did not warn the user th…7.8
- CVE-2023-37209A use-after-free condition existed in `NotifyOnHistoryReload…8.8
- CVE-2023-3721The WP-EMail WordPress plugin before 2.69.1 does not sanitis…4.8
Are you affected by CVE-2023-37204?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
