2023 CVE Vulnerabilities

31,411 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-32205MEDIUM4.3In multiple cases browser prompts could have been obscured by popups controlled by content. These could have led to pote...
CVE-2023-29551HIGH8.8Memory safety bugs present in Firefox 111. Some of these bugs showed evidence of memory corruption and we presume that w...
CVE-2023-29550HIGH8.8Memory safety bugs present in Firefox 111 and Firefox ESR 102.9. Some of these bugs showed evidence of memory corruption...
CVE-2023-29549MEDIUM6.5Under certain circumstances, a call to the <code>bind</code> function may have resulted in the incorrect realm. This may...
CVE-2023-29548MEDIUM6.5A wrong lowering instruction in the ARM64 Ion compiler resulted in a wrong optimization result. This vulnerability affec...
CVE-2023-29547MEDIUM6.5When a secure cookie existed in the Firefox cookie jar an insecure cookie for the same domain could have been created, w...
CVE-2023-29544MEDIUM6.5If multiple instances of resource exhaustion occurred at the incorrect time, the garbage collector could have caused mem...
CVE-2023-29543HIGH8.8An attacker could have caused memory corruption and a potentially exploitable use-after-free of a pointer in a global ob...
CVE-2023-29541HIGH8.8Firefox did not properly handle downloads of files ending in <code>.desktop</code>, which can be interpreted to run atta...
CVE-2023-29540MEDIUM6.1Using a redirect embedded into <code>sourceMappingUrls</code> could allow for navigation to external protocol links in s...
CVE-2023-29539HIGH8.8When handling the filename directive in the Content-Disposition header, the filename would be truncated if the filename ...
CVE-2023-29538MEDIUM4.3Under specific circumstances a WebExtension may have received a <code>jar:file:///</code> URI instead of a <code>moz-ext...
CVE-2023-29537HIGH7.5Multiple race conditions in the font initialization could have led to memory corruption and execution of attacker-contro...
CVE-2023-29536HIGH8.8An attacker could cause the memory manager to incorrectly free a pointer that addresses attacker-controlled memory, resu...
CVE-2023-29535MEDIUM6.5Following a Garbage Collector compaction, weak maps may have been accessed before they were correctly traced. This resul...
CVE-2023-29533MEDIUM4.3A website could have obscured the fullscreen notification by using a combination of <code>window.open</code>, fullscreen...
CVE-2023-28177HIGH8.8Memory safety bugs present in Firefox 110. Some of these bugs showed evidence of memory corruption and we presume that w...
CVE-2023-28176HIGH8.8Memory safety bugs present in Firefox 110 and Firefox ESR 102.8. Some of these bugs showed evidence of memory corruption...
CVE-2023-28164MEDIUM6.5Dragging a URL from a cross-origin iframe that was removed during the drag could have led to user confusion and website ...
CVE-2023-28163MEDIUM6.5When downloading files through the Save As dialog on Windows with suggested filenames containing environment variable na...
CVE-2023-28162HIGH8.8While implementing AudioWorklets, some code may have casted one type to another, invalid, dynamic type. This could have ...
CVE-2023-28161HIGH8.8If temporary "one-time" permissions, such as the ability to use the Camera, were granted to a document loaded using a fi...
CVE-2023-28160MEDIUM6.5When following a redirect to a publicly accessible web extension file, the URL may have been translated to the actual lo...
CVE-2023-28159MEDIUM4.3The fullscreen notification could have been hidden on Firefox for Android by using download popups, resulting in potenti...
CVE-2023-25752MEDIUM6.5When accessing throttled streams, the count of available bytes needed to be checked in the calling function to be within...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now