2023 CVE Vulnerabilities

31,411 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-25751MEDIUM6.5Sometimes, when invalidating JIT code while following an iterator, the newly generated code could be overwritten incorre...
CVE-2023-25750MEDIUM4.3Under certain circumstances, a ServiceWorker's offline cache may have leaked to the file system when using private brows...
CVE-2023-25749MEDIUM4.3Android applications with unpatched vulnerabilities can be launched from a browser using Intents, exposing users to thes...
CVE-2023-25748MEDIUM4.3By displaying a prompt with a long description, the fullscreen notification could have been hidden, resulting in potenti...
CVE-2023-25746HIGH8.8Memory safety bugs present in Firefox ESR 102.7. Some of these bugs showed evidence of memory corruption and we presume ...
CVE-2023-25745HIGH8.8Memory safety bugs present in Firefox 109. Some of these bugs showed evidence of memory corruption and we presume that w...
CVE-2023-25744HIGH8.8Mmemory safety bugs present in Firefox 109 and Firefox ESR 102.7. Some of these bugs showed evidence of memory corruptio...
CVE-2023-25743HIGH7.5A lack of in app notification for entering fullscreen mode could have lead to a malicious website spoofing browser chrom...
CVE-2023-25742MEDIUM6.5When importing a SPKI RSA public key as ECDSA P-256, the key would be handled incorrectly causing the tab to crash. This...
CVE-2023-25741MEDIUM6.5When dragging and dropping an image cross-origin, the image's size could potentially be leaked. This behavior was shippe...
CVE-2023-25740HIGH8.8After downloading a Windows <code>.scf</code> script from the local filesystem, an attacker could supply a remote path t...
CVE-2023-25739HIGH8.8Module load requests that failed were not being checked as to whether or not they were cancelled causing a use-after-fre...
CVE-2023-25738MEDIUM6.5Members of the <code>DEVMODEW</code> struct set by the printer device driver weren't being validated and could have resu...
CVE-2023-25737HIGH8.8An invalid downcast from <code>nsTextNode</code> to <code>SVGElement</code> could have lead to undefined behavior. This ...
CVE-2023-25735HIGH8.8Cross-compartment wrappers wrapping a scripted proxy could have caused objects from other compartments to be stored in t...
CVE-2023-25734HIGH8.1After downloading a Windows <code>.url</code> shortcut from the local filesystem, an attacker could supply a remote path...
CVE-2023-25732HIGH8.8When encoding data from an <code>inputStream</code> in <code>xpcom</code> the size of the input being encoded was not co...
CVE-2023-25731HIGH8.8Due to URL previews in the network panel of developer tools improperly storing URLs, query parameters could potentially ...
CVE-2023-25730MEDIUM5.4A background script invoking <code>requestFullscreen</code> and then blocking the main thread could force the browser in...
CVE-2023-25729HIGH8.8Permission prompts for opening external schemes were only shown for <code>ContentPrincipals</code> resulting in extensio...
CVE-2023-25728MEDIUM6.5The <code>Content-Security-Policy-Report-Only</code> header could allow an attacker to leak a child iframe's unredacted ...
CVE-2023-23606HIGH8.8Mozilla developers and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 108. Some of these bugs s...
CVE-2023-23605HIGH8.8Mozilla developers and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 108 and Firefox ESR 102.6...
CVE-2023-23604MEDIUM6.5A duplicate `SystemPrincipal` object could be created when parsing a non-system html document via `DOMParser::ParseFromS...
CVE-2023-23603MEDIUM6.5Regular expressions used to filter out forbidden properties and values from style directives in calls to `console.log` w...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now