{ "id": "CVE-2023-5175", "sourceIdentifier": "security@mozilla.org", "published": "2023-09-27T15:19:42.630", "lastModified": "2024-01-07T11:15:14.073", "vulnStatus": "Modified", "cveTags": [], "descriptions": [ { "lang": "en", "value": "During process shutdown, it was possible that an `ImageBitmap` was created that would later be used after being freed from a different codepath, leading to a potentially exploitable crash. This vulnerability affects Firefox < 118." }, { "lang": "es", "value": "Durante el cierre del proceso, era posible que se creara un \"ImageBitmap\" que luego se usar\u00eda despu\u00e9s de liberarse de una ruta de c\u00f3digo diferente, lo que provocar\u00eda un bloqueo potencialmente explotable. Esta vulnerabilidad afecta a Firefox < 118." } ], "metrics": { "cvssMetricV31": [ { "source": "nvd@nist.gov", "type": "Primary", "cvssData": { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH", "baseScore": 9.8, "baseSeverity": "CRITICAL" }, "exploitabilityScore": 3.9, "impactScore": 5.9 } ] }, "weaknesses": [ { "source": "nvd@nist.gov", "type": "Primary", "description": [ { "lang": "en", "value": "CWE-416" } ] } ], "configurations": [ { "nodes": [ { "operator": "OR", "negate": false, "cpeMatch": [ { "vulnerable": true, "criteria": "cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*", "versionEndExcluding": "118", "matchCriteriaId": "2216A424-94E2-45E7-BB95-646BFC8182E1" } ] } ] } ], "references": [ { "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1849704", "source": "security@mozilla.org", "tags": [ "Broken Link" ] }, { "url": "https://security.gentoo.org/glsa/202401-10", "source": "security@mozilla.org" }, { "url": "https://www.mozilla.org/security/advisories/mfsa2023-41/", "source": "security@mozilla.org", "tags": [ "Vendor Advisory" ] } ] }