CVE-2023-4573
When receiving rendering data over IPC `mStream` could have been destroyed when initialized, which could have led to a u
When receiving rendering data over IPC mStream could have been destroyed when initialized, which could have led to a use-after-free causing a potentially exploitable crash. This vulnerability affects Firefox < 117, Firefox ESR < 102.15, Firefox ESR < 115.2, Thunderbird < 102.15, and Thunderbird < 115.2.
MEDIUM · CVSS 6.5
EPSS 0.00137
Schedule remediation
- SSVC automatable: yes - attacks can be scripted at scale
Sigma rules1
YARA rules0