VDB
CVE-2023-4057
CVE-2023-4057
PUBLISHED
In Mozilla Firefox und Mozilla Firefox ESR und Mozilla Thunderbird existieren mehrere Schwachstellen. Diese sind auf verschiedene Fehlertypen, z.B. Speicherfehler oder Use-after-Free-Fehler zurückzuführen. Ein entfernter, anonymer Angreifer kann diese Schwachstellen ausnutzen, um beliebigen Programmcode auszuführen, seine Privilegien zu erweitern, Informationen offenzulegen, Dateien zu manipulieren, einen Denial of Service Zustand herbeizuführen oder Sicherheitsvorkehrungen zu umgehen. Zur erfolgreichen Ausnutzung ist eine Benutzeraktion erforderlich.
EPSS 0.23% · 45.9th percentile
Risk Scores
EPSS Score
0.23%
45.9th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Oracle | Oracle Linux | |
| Ubuntu | Ubuntu Linux | |
| Amazon | Amazon Linux 2 | |
| Xerox | Xerox FreeFlow Print Server v9 | |
| SUSE | SUSE Linux | |
| Fedora | Fedora Linux | |
| Xerox | Xerox FreeFlow Print Server v7 | |
| Xerox | Xerox FreeFlow Print Server v2 / Windows 10 | |
| Gentoo | Gentoo Linux | |
| Debian | Debian Linux | |
| Red Hat | Red Hat Enterprise Linux |
Exploit Intelligence
- Weaponized CVE-2023-4057 in Nuclei (cve.org)
Timeline
- Jul 12, 2023 Nuclei Template
- Jul 12, 2023 Fix Commit
- Aug 1, 2023 CVE Published
- Aug 2, 2023 EPSS Score
- Sep 5, 2023 EPSS Score
- Oct 9, 2023 EPSS Score
- Dec 15, 2023 EPSS Score
- Jan 18, 2024 EPSS Score
- Feb 21, 2024 EPSS Score
- Mar 26, 2024 EPSS Score
- Apr 29, 2024 EPSS Score
- Jul 5, 2024 EPSS Score
References
- https://wid.cert-bund.de/.well-known/csaf/white/2023/wid-sec-w-2023-1934.json advisory
- https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2023-1934 advisory
- https://www.mozilla.org/en-US/security/advisories/mfsa2023-29/ advisory
- https://www.mozilla.org/en-US/security/advisories/mfsa2023-30/ advisory
- https://www.mozilla.org/en-US/security/advisories/mfsa2023-31/ advisory
- https://ubuntu.com/security/notices/USN-6267-1 advisory
- https://lists.suse.com/pipermail/sle-security-updates/2023-August/015759.html advisory
- https://www.mozilla.org/en-US/security/advisories/mfsa2023-32/ advisory
- https://www.mozilla.org/en-US/security/advisories/mfsa2023-33/ advisory
- https://lists.suse.com/pipermail/sle-security-updates/2023-August/015760.html advisory
- https://lists.suse.com/pipermail/sle-security-updates/2023-August/015758.html advisory
- https://access.redhat.com/errata/RHSA-2023:4462 advisory
- https://access.redhat.com/errata/RHSA-2023:4463 advisory
- https://access.redhat.com/errata/RHSA-2023:4464 advisory
- https://access.redhat.com/errata/RHSA-2023:4465 advisory
- https://access.redhat.com/errata/RHSA-2023:4460 advisory
- https://access.redhat.com/errata/RHSA-2023:4468 advisory
- https://access.redhat.com/errata/RHSA-2023:4469 advisory
- https://access.redhat.com/errata/RHSA-2023:4461 advisory
- https://lists.debian.org/debian-security-announce/2023/msg00156.html advisory
…and 38 more