Description
The `ShutdownObserver()` was susceptible to potentially undefined behavior due to its reliance on a dynamic type that lacked a virtual destructor. This vulnerability affects Firefox ESR < 115.6, Thunderbird < 115.6, and Firefox < 121.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-3697-1 | firefox-esr security update |
Debian DSA |
DSA-5581-1 | firefox-esr security update |
Ubuntu USN |
USN-6562-1 | Firefox vulnerabilities |
Ubuntu USN |
USN-6563-1 | Thunderbird vulnerabilities |
References
History
No history.
Status: PUBLISHED
Assigner: mozilla
Published:
Updated: 2025-02-13T17:26:37.799Z
Reserved: 2023-12-15T17:42:56.329Z
Link: CVE-2023-6863
No data.
Status : Modified
Published: 2023-12-19T14:15:07.650
Modified: 2026-06-17T06:51:34.237
Link: CVE-2023-6863
OpenCVE Enrichment
No data.
Weaknesses
-
CWE-20
Improper Input Validation
- NVD-CWE-noinfo
Debian DLA
Debian DSA
Ubuntu USN