CVE-2023-4058 identifies memory safety bugs in Firefox versions prior to 116, which could lead to memory corruption and potentially arbitrary code execution. This critical vulnerability, rated 9.8 CVSS, is easily exploitable over the network with no user interaction required, posing a significant risk of complete compromise of confidentiality, integrity, and availability. While there is no evidence of active exploitation or public exploit code, the vulnerability has garnered substantial community discussion and media attention, indicating its perceived importance.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 116CPE match | cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:* | ||
< 116.0CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.