Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2023-55353
HistoryApr 17, 2023 - 12:00 a.m.

Mozilla Firefox ESR Denial of Service Vulnerability (CNVD-2023-55353)

2023-04-1700:00:00
China National Vulnerability Database
www.cnvd.org.cn
9
mozilla firefox esr
denial of service
vulnerability
memory corruption
exploitable crash
mozilla foundation
weak maps

EPSS

0.001

Percentile

48.6%

Mozilla Firefox ESR is an extended support release of Firefox (web browser) from the Mozilla Foundation in the United States. A denial of service vulnerability exists in Mozilla Firefox ESR prior to version 102.10, which originates from a garbage collector compression where weak maps may be accessed before they are properly tracked, and can be exploited by an attacker to cause memory corruption and a potentially exploitable crash.