Security Advisory

CVE-2023-4577

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2023-09-11 08:01:02
Last updated 2025-12-18 15:23:09
Assigner mozilla
CVSS score not scored
State PUBLISHED

Description

When `UpdateRegExpStatics` attempted to access `initialStringHeap` it could already have been garbage collected prior to entering the function, which could potentially have led to an exploitable crash. This vulnerability affects Firefox < 117, Firefox ESR < 115.2, and Thunderbird < 115.2.