NA

CVE-2023-23597

Published: 02/06/2023 Updated: 08/06/2023
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

A compromised web child process could disable web security opening restrictions, leading to a new child process being spawned within the <code>file://</code> context. Given a reliable exploit primitive, this new process could be exploited again leading to arbitrary file read. This vulnerability affects Firefox < 109.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

mozilla firefox

Vendor Advisories

Several security issues were fixed in Firefox ...
Mozilla Foundation Security Advisory 2023-01 Security Vulnerabilities fixed in Firefox 109 Announced January 17, 2023 Impact high Products Firefox Fixed in Firefox 109 ...