2023 CVE Vulnerabilities
31,248 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-3070 | MEDIUM | 5.4 | 0.6% | Jun 2, 2023 | Cross-site Scripting (XSS) - Stored in GitHub repository tsolucio/corebos prior to 8. |
| CVE-2023-32212 | MEDIUM | 4.3 | 0.6% | Jun 2, 2023 | An attacker could have positioned a `datalist` element to obscure the address bar. This vulnerability affects Firefox < ... |
| CVE-2023-32211 | MEDIUM | 6.5 | 0.7% | Jun 2, 2023 | A type checking bug would have led to invalid code being compiled. This vulnerability affects Firefox < 113, Firefox ESR... |
| CVE-2023-32206 | MEDIUM | 6.5 | 0.7% | Jun 2, 2023 | An out-of-bound read could have led to a crash in the RLBox Expat driver. This vulnerability affects Firefox < 113, Fire... |
| CVE-2023-32205 | MEDIUM | 4.3 | 0.6% | Jun 2, 2023 | In multiple cases browser prompts could have been obscured by popups controlled by content. These could have led to pote... |
| CVE-2023-29549 | MEDIUM | 6.5 | 0.3% | Jun 2, 2023 | Under certain circumstances, a call to the <code>bind</code> function may have resulted in the incorrect realm. This may... |
| CVE-2023-29548 | MEDIUM | 6.5 | 0.7% | Jun 2, 2023 | A wrong lowering instruction in the ARM64 Ion compiler resulted in a wrong optimization result. This vulnerability affec... |
| CVE-2023-29547 | MEDIUM | 6.5 | 0.5% | Jun 2, 2023 | When a secure cookie existed in the Firefox cookie jar an insecure cookie for the same domain could have been created, w... |
| CVE-2023-29544 | MEDIUM | 6.5 | 0.4% | Jun 2, 2023 | If multiple instances of resource exhaustion occurred at the incorrect time, the garbage collector could have caused mem... |
| CVE-2023-29540 | MEDIUM | 6.1 | 0.3% | Jun 2, 2023 | Using a redirect embedded into <code>sourceMappingUrls</code> could allow for navigation to external protocol links in s... |
| CVE-2023-29538 | MEDIUM | 4.3 | 0.4% | Jun 2, 2023 | Under specific circumstances a WebExtension may have received a <code>jar:file:///</code> URI instead of a <code>moz-ext... |
| CVE-2023-29535 | MEDIUM | 6.5 | 0.7% | Jun 2, 2023 | Following a Garbage Collector compaction, weak maps may have been accessed before they were correctly traced. This resul... |
| CVE-2023-29533 | MEDIUM | 4.3 | 0.6% | Jun 2, 2023 | A website could have obscured the fullscreen notification by using a combination of <code>window.open</code>, fullscreen... |
| CVE-2023-28164 | MEDIUM | 6.5 | 0.3% | Jun 2, 2023 | Dragging a URL from a cross-origin iframe that was removed during the drag could have led to user confusion and website ... |
| CVE-2023-28163 | MEDIUM | 6.5 | 0.8% | Jun 2, 2023 | When downloading files through the Save As dialog on Windows with suggested filenames containing environment variable na... |
| CVE-2023-28160 | MEDIUM | 6.5 | 0.5% | Jun 2, 2023 | When following a redirect to a publicly accessible web extension file, the URL may have been translated to the actual lo... |
| CVE-2023-28159 | MEDIUM | 4.3 | 0.3% | Jun 2, 2023 | The fullscreen notification could have been hidden on Firefox for Android by using download popups, resulting in potenti... |
| CVE-2023-25752 | MEDIUM | 6.5 | 0.6% | Jun 2, 2023 | When accessing throttled streams, the count of available bytes needed to be checked in the calling function to be within... |
| CVE-2023-25751 | MEDIUM | 6.5 | 0.7% | Jun 2, 2023 | Sometimes, when invalidating JIT code while following an iterator, the newly generated code could be overwritten incorre... |
| CVE-2023-25750 | MEDIUM | 4.3 | 0.5% | Jun 2, 2023 | Under certain circumstances, a ServiceWorker's offline cache may have leaked to the file system when using private brows... |
| CVE-2023-25749 | MEDIUM | 4.3 | 0.4% | Jun 2, 2023 | Android applications with unpatched vulnerabilities can be launched from a browser using Intents, exposing users to thes... |
| CVE-2023-25748 | MEDIUM | 4.3 | 0.3% | Jun 2, 2023 | By displaying a prompt with a long description, the fullscreen notification could have been hidden, resulting in potenti... |
| CVE-2023-25742 | MEDIUM | 6.5 | 0.6% | Jun 2, 2023 | When importing a SPKI RSA public key as ECDSA P-256, the key would be handled incorrectly causing the tab to crash. This... |
| CVE-2023-25741 | MEDIUM | 6.5 | 0.8% | Jun 2, 2023 | When dragging and dropping an image cross-origin, the image's size could potentially be leaked. This behavior was shippe... |
| CVE-2023-25738 | MEDIUM | 6.5 | 0.6% | Jun 2, 2023 | Members of the <code>DEVMODEW</code> struct set by the printer device driver weren't being validated and could have resu... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now