2023 CVE Vulnerabilities

31,248 CVEs published in 2023.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2023-3070MEDIUM5.4Cross-site Scripting (XSS) - Stored in GitHub repository tsolucio/corebos prior to 8.
CVE-2023-32212MEDIUM4.3An attacker could have positioned a `datalist` element to obscure the address bar. This vulnerability affects Firefox < ...
CVE-2023-32211MEDIUM6.5A type checking bug would have led to invalid code being compiled. This vulnerability affects Firefox < 113, Firefox ESR...
CVE-2023-32206MEDIUM6.5An out-of-bound read could have led to a crash in the RLBox Expat driver. This vulnerability affects Firefox < 113, Fire...
CVE-2023-32205MEDIUM4.3In multiple cases browser prompts could have been obscured by popups controlled by content. These could have led to pote...
CVE-2023-29549MEDIUM6.5Under certain circumstances, a call to the <code>bind</code> function may have resulted in the incorrect realm. This may...
CVE-2023-29548MEDIUM6.5A wrong lowering instruction in the ARM64 Ion compiler resulted in a wrong optimization result. This vulnerability affec...
CVE-2023-29547MEDIUM6.5When a secure cookie existed in the Firefox cookie jar an insecure cookie for the same domain could have been created, w...
CVE-2023-29544MEDIUM6.5If multiple instances of resource exhaustion occurred at the incorrect time, the garbage collector could have caused mem...
CVE-2023-29540MEDIUM6.1Using a redirect embedded into <code>sourceMappingUrls</code> could allow for navigation to external protocol links in s...
CVE-2023-29538MEDIUM4.3Under specific circumstances a WebExtension may have received a <code>jar:file:///</code> URI instead of a <code>moz-ext...
CVE-2023-29535MEDIUM6.5Following a Garbage Collector compaction, weak maps may have been accessed before they were correctly traced. This resul...
CVE-2023-29533MEDIUM4.3A website could have obscured the fullscreen notification by using a combination of <code>window.open</code>, fullscreen...
CVE-2023-28164MEDIUM6.5Dragging a URL from a cross-origin iframe that was removed during the drag could have led to user confusion and website ...
CVE-2023-28163MEDIUM6.5When downloading files through the Save As dialog on Windows with suggested filenames containing environment variable na...
CVE-2023-28160MEDIUM6.5When following a redirect to a publicly accessible web extension file, the URL may have been translated to the actual lo...
CVE-2023-28159MEDIUM4.3The fullscreen notification could have been hidden on Firefox for Android by using download popups, resulting in potenti...
CVE-2023-25752MEDIUM6.5When accessing throttled streams, the count of available bytes needed to be checked in the calling function to be within...
CVE-2023-25751MEDIUM6.5Sometimes, when invalidating JIT code while following an iterator, the newly generated code could be overwritten incorre...
CVE-2023-25750MEDIUM4.3Under certain circumstances, a ServiceWorker's offline cache may have leaked to the file system when using private brows...
CVE-2023-25749MEDIUM4.3Android applications with unpatched vulnerabilities can be launched from a browser using Intents, exposing users to thes...
CVE-2023-25748MEDIUM4.3By displaying a prompt with a long description, the fullscreen notification could have been hidden, resulting in potenti...
CVE-2023-25742MEDIUM6.5When importing a SPKI RSA public key as ECDSA P-256, the key would be handled incorrectly causing the tab to crash. This...
CVE-2023-25741MEDIUM6.5When dragging and dropping an image cross-origin, the image's size could potentially be leaked. This behavior was shippe...
CVE-2023-25738MEDIUM6.5Members of the <code>DEVMODEW</code> struct set by the printer device driver weren't being validated and could have resu...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now