Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2023-68210
HistoryAug 03, 2023 - 12:00 a.m.

Mozilla Firefox and Firefox ESR Buffer Overflow Vulnerability

2023-08-0300:00:00
China National Vulnerability Database
www.cnvd.org.cn
10
mozilla firefox
firefox esr
buffer overflow
mozilla foundation
open source
vulnerability
untrusted input
stack buffer
sandbox escape
exploitable crash
security

EPSS

0.002

Percentile

58.3%

Mozilla Firefox is an open source web browser from the Mozilla Foundation in the U.S. Mozilla Firefox ESR is Firefox (Enterprise Edition). Mozilla Firefox and Mozilla Firefox ESR suffer from a buffer overflow vulnerability that stems from the fact that, under certain circumstances, untrusted input streams are copied to the stack buffer without checking their size. An attacker could use this vulnerability to cause a potentially exploitable crash that could lead to a sandbox escape.