Cyber Resilience

CVE-2023-29550

Mozilla Firefox ≤ 112.0

Published
02 June 2023
Modified
10 January 2025
Patch / advisory
CVSS Score v3.1 8.8
Click a component to see what it means
Raw vectorCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS Score 0.0070 50th percentile
Risk Priority 65 floored blend · peak EPSS

Summary

CVE-2023-29550 is a high-severity an unspecified weakness vulnerability in Mozilla Firefox. Its CVSS base score is 8.8 (High).

Operationally, ranked in the top 50% of CVEs by exploit likelihood; it is not currently listed in the CISA KEV catalog.

EU & UK References

Vulnerability Data

Memory safety bugs present in Firefox 111 and Firefox ESR 102.9. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability…

more

affects Firefox < 112, Focus for Android < 112, Firefox ESR < 102.10, Firefox for Android < 112, and Thunderbird < 102.10.

CWE(s)

Related Threats

CVEs Like This One

CVE-2023-29541Same product: Mozilla Firefox
CVE-2023-29535Same product: Mozilla Firefox
CVE-2023-29536Same product: Mozilla Firefox
CVE-2023-29539Same product: Mozilla Firefox
CVE-2023-29533Same product: Mozilla Firefox
CVE-2023-29548Same product: Mozilla Firefox
CVE-2023-28164Same product: Mozilla Firefox
CVE-2023-32211Same product: Mozilla Firefox
CVE-2023-32212Same product: Mozilla Firefox
CVE-2023-25752Same product: Mozilla Firefox

Affected Assets

mozilla
firefox
≤ 112.0 · ≤ 112.0
mozilla
firefox esr
≤ 102.10
mozilla
focus
≤ 112.0
mozilla
thunderbird
≤ 102.10

Mitigating Controls

No mitigating controls mapped yet. The per-CVE control annotator has not reached this CVE.

References