8.6
CVSSv3

CVE-2023-4576

Published: 11/09/2023 Updated: 13/09/2023
CVSS v3 Base Score: 8.6 | Impact Score: 4 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

On Windows, an integer overflow could occur in `RecordedSourceSurfaceCreation` which resulted in a heap buffer overflow potentially leaking sensitive data that could have led to a sandbox escape. *This bug only affects Firefox on Windows. Other operating systems are unaffected.* This vulnerability affects Firefox < 117, Firefox ESR < 102.15, Firefox ESR < 115.2, Thunderbird < 102.15, and Thunderbird < 115.2.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

mozilla firefox

mozilla firefox_esr

mozilla thunderbird

Vendor Advisories

Description<!----> This CVE is under investigation by Red Hat Product Security ...
Mozilla Foundation Security Advisory 2023-38 Security Vulnerabilities fixed in Thunderbird 1152 Announced August 29, 2023 Impact high Products Thunderbird Fixed in Thunderbird 1152 ...
Mozilla Foundation Security Advisory 2023-37 Security Vulnerabilities fixed in Thunderbird 10215 Announced August 29, 2023 Impact high Products Thunderbird Fixed in Thunderbird 10215 ...
Mozilla Foundation Security Advisory 2023-34 Security Vulnerabilities fixed in Firefox 117 Announced August 29, 2023 Impact high Products Firefox Fixed in Firefox 117 ...
Mozilla Foundation Security Advisory 2023-35 Security Vulnerabilities fixed in Firefox ESR 10215 Announced August 29, 2023 Impact high Products Firefox ESR Fixed in Firefox ESR 10215 ...
Mozilla Foundation Security Advisory 2023-36 Security Vulnerabilities fixed in Firefox ESR 1152 Announced August 29, 2023 Impact high Products Firefox ESR Fixed in Firefox ESR 1152 ...