CVE-2023-29549
Gentoo Linux Security Advisory 202305-35
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Under certain circumstances, a call to the <code>bind</code> function may have resulted in the incorrect realm. This may have created a vulnerability relating to JavaScript-implemented sandboxes such as SES. This vulnerability affects Firefox for Android < 112, Firefox < 112, and Focus for Android < 112.
Multiple security issues were discovered in Firefox. If a user were tricked into opening a specially crafted website, an attacker could potentially exploit these to cause a denial of service, obtain sensitive information across domains, or execute arbitrary code. Irvan Kurniawan discovered that Firefox did not properly manage fullscreen notifications using a combination of window.open, fullscreen requests, window.name assignments, and setInterval calls. An attacker could potentially exploit this issue to perform spoofing attacks.
CVSS Scores
SSVC
- Decision:Track
Timeline
- 2023-04-07 CVE Reserved
- 2023-04-12 CVE Published
- 2025-01-10 CVE Updated
- 2026-04-26 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-326: Inadequate Encryption Strength
CAPEC
References (2)
| URL | Tag | Source |
|---|---|---|
| https://bugzilla.mozilla.org/show_bug.cgi?id=1823042 | Issue Tracking |
| URL | Date | SRC |
|---|
| URL | Date | SRC |
|---|
| URL | Date | SRC |
|---|---|---|
| https://www.mozilla.org/security/advisories/mfsa2023-13 | 2023-06-09 |
Affected Vendors, Products, and Versions
| Vendor | Product | Version | Other | Status | ||||||
|---|---|---|---|---|---|---|---|---|---|---|
| Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
| Mozilla Search vendor "Mozilla" | Firefox Search vendor "Mozilla" for product "Firefox" | < 112.0 Search vendor "Mozilla" for product "Firefox" and version " < 112.0" | - |
Affected
| ||||||
| Mozilla Search vendor "Mozilla" | Firefox Search vendor "Mozilla" for product "Firefox" | < 112.0 Search vendor "Mozilla" for product "Firefox" and version " < 112.0" | android |
Affected
| ||||||
| Mozilla Search vendor "Mozilla" | Focus Search vendor "Mozilla" for product "Focus" | < 112.0 Search vendor "Mozilla" for product "Focus" and version " < 112.0" | android |
Affected
| ||||||
