On Windows, an integer overflow... CVE-2023-4576

- AV AC AU C I A
发布: 2023-09-11
修订: 2023-09-13

On Windows, an integer overflow could occur in `RecordedSourceSurfaceCreation` which resulted in a heap buffer overflow potentially leaking sensitive data that could have led to a sandbox escape. *This bug only affects Firefox on Windows. Other operating systems are unaffected.* This vulnerability affects Firefox < 117, Firefox ESR < 102.15, Firefox ESR < 115.2, Thunderbird < 102.15, and Thunderbird < 115.2.

0%
暂无可用Exp或PoC
当前有5条受影响产品信息