Mozilla developers and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 108 and Firefox ESR 102.6. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 109, Firefox ESR < 102.7, and Thunderbird < 102.7.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-3275-1 | firefox-esr security update |
Debian DLA |
DLA-3324-1 | thunderbird security update |
Debian DSA |
DSA-5322-1 | firefox-esr security update |
Debian DSA |
DSA-5355-1 | thunderbird security update |
EUVD |
EUVD-2023-27705 | Memory safety bugs present in Firefox 108 and Firefox ESR 102.6. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 109, Thunderbird < 102.7, and Firefox ESR < 102.7. |
Ubuntu USN |
USN-5816-1 | Firefox vulnerabilities |
Ubuntu USN |
USN-5824-1 | Thunderbird vulnerabilities |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Thu, 18 Dec 2025 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Memory safety bugs present in Firefox 108 and Firefox ESR 102.6. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 109, Thunderbird < 102.7, and Firefox ESR < 102.7. | Mozilla developers and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 108 and Firefox ESR 102.6. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 109, Firefox ESR < 102.7, and Thunderbird < 102.7. |
| Title | Mozilla: Memory safety bugs fixed in Firefox 109 and Firefox ESR 102.7 | Memory safety bugs fixed in Firefox 109 and Firefox ESR 102.7 |
Fri, 10 Jan 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mozilla
Published:
Updated: 2025-12-18T15:22:58.781Z
Reserved: 2023-01-16T00:00:00
Link: CVE-2023-23605
Updated: 2024-08-02T10:35:33.330Z
Status : Modified
Published: 2023-06-02T17:15:10.907
Modified: 2025-12-18T16:15:49.217
Link: CVE-2023-23605
OpenCVE Enrichment
No data.
Debian DLA
Debian DSA
EUVD
Ubuntu USN