CVE-2023-25744: High severity firefox vulnerability
Last updated 24 July 2024
Other sources
Mmemory safety bugs present in Firefox 109 and Firefox ESR 102.7. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 110 and Firefox ESR < 102.8.
Mozilla developers Kershaw Chang and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 109 and Firefox ESR 102.7. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code.
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is CVE-2023-25744?
CVE-2023-25744 is a vulnerability in Firefox 109 and Firefox ESR 102.7 that allows for memory corruption and potential code execution.
How severe is the vulnerability CVE-2023-25744?
The severity of CVE-2023-25744 is rated as high, with a CVSS score of 8.8.
Which software versions are affected by CVE-2023-25744?
Firefox versions up to exclusive 110, Firefox ESR versions up to exclusive 102.8, and various Red Hat and Ubuntu packages are affected.
How do I fix CVE-2023-25744 in Firefox?
To fix CVE-2023-25744 in Firefox, update to version 110 or higher.
Where can I find additional information about CVE-2023-25744?
Additional information about CVE-2023-25744 can be found in the Mozilla Bugzilla and Mozilla security advisories.