CVE-2023-25746
Public on 2023-02-15
        Modified on 2024-02-10
        
      Description
            
              Mozilla Foundation Security Advisory:
Mozilla developers Philipp and Gabriele Svelto reported memory safety bugs present in Firefox ESR 102.7. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code.
          Mozilla developers Philipp and Gabriele Svelto reported memory safety bugs present in Firefox ESR 102.7. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code.
Severity
          
          See what this means
        CVSS v3 Base Score
          
          See breakdown
        Affected Packages
| Platform | Package | Release Date | Advisory | Status | 
|---|---|---|---|---|
| Amazon Linux 2 - Firefox Extra | firefox | 2023-09-25 | ALAS2FIREFOX-2023-007 | Fixed | 
| Amazon Linux 2 - Core | thunderbird | 2023-03-06 | ALAS2-2023-1983 | Fixed | 
CVSS Scores
| Score Type | Score | Vector | |
|---|---|---|---|
| Amazon Linux | CVSSv3 | 7.5 | AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H | 
| NVD | CVSSv3 | 8.8 | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |