A hashtable in the Ion Engine could have been mutated while there was a live interior reference, leading to a potential use-after-free and exploitable crash. This vulnerability affects Firefox < 118.
CVSS Details
- CVSS 3.1 Base Score: 9.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Gentoo Linux | — | Upgrade www-client/firefox-bin.Upgrade www-client/firefox. | Jan 8, 2024 | Sep 27, 2023 |
| Mfsa2023 41 | — | Upgrade to Mozilla Firefox version 118.0Upgrade to the latest version of Mozilla Firefox | Sep 27, 2023 | Sep 26, 2023 |
| Ubuntu | — | Upgrade firefox | Oct 4, 2023 | Sep 27, 2023 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub