CVE-2023-6868
Mozilla Firefox ≤ 121.0
CVSS Score v3.1
4.3
Click a component to see what it means
Raw vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
EPSS Score
0.0049
40th percentile
Summary
CVE-2023-6868 is a medium-severity an unspecified weakness vulnerability in Mozilla Firefox. Its CVSS base score is 4.3 (Medium).
Operationally, ranked at the 40th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog.
EU & UK References
- 🇪🇺 ENISA EUVD: EUVD-2023-59072
Vulnerability Data
In some instances, the user-agent would allow push requests which lacked a valid VAPID even though the push manager subscription defined one. This could allow empty messages to be sent from unauthorized parties. *This bug only affects Firefox on Android.*…
more
This vulnerability affects Firefox < 121.
- CWE(s)
Related Threats
CVEs Like This One
CVE-2024-4766Same product: Google Android
CVE-2025-11718Same product: Google Android
CVE-2025-0246Same product: Google Android
CVE-2025-8042Same product: Google Android
CVE-2025-6431Same product: Google Android
CVE-2025-11720Same product: Google Android
CVE-2025-11717Same product: Google Android
CVE-2024-8388Same product: Google Android
CVE-2025-8041Same product: Google Android
CVE-2025-8364Same product: Google Android
Affected Assets
mozilla
firefox
≤ 121.0
Mitigating Controls
No mitigating controls mapped yet. The per-CVE control annotator has not reached this CVE.