Irvan Kurniawan calling JS::CheckRegExpSyntax a Syntax Error could have been set which would end in calling convertToRuntimeErrorAndClear. #CVE-2023-4578: Error reporting methods in SpiderMonkey could have triggered an Out of Memory Exception When UpdateRegExpStatics attempted to access initialStringHeap it could already have been garbage collected prior to entering the function, which could potentially have led to an exploitable crash. #CVE-2023-4577: Memory corruption in JIT UpdateRegExpStatics This bug only affects Firefox on Windows. On Windows, an integer overflow could occur in RecordedSourceSurfaceCreation which resulted in a heap buffer overflow potentially leaking sensitive data that could have led to a sandbox escape. #CVE-2023-4576: Integer Overflow in RecordedSourceSurfaceCreation This could have led to a use-after-free causing a potentially exploitable crash. When creating a callback over IPC for showing the File Picker window, multiple of the same callbacks could have been created at a time and eventually all simultaneously destroyed as soon as one of the callbacks finished. #CVE-2023-4575: Memory corruption in IPC FilePickerShownCallback When creating a callback over IPC for showing the Color Picker window, multiple of the same callbacks could have been created at a time and eventually all simultaneously destroyed as soon as one of the callbacks finished. #CVE-2023-4574: Memory corruption in IPC ColorPickerShownCallback When receiving rendering data over IPC mStream could have been destroyed when initialized, which could have led to a use-after-free causing a potentially exploitable crash. #CVE-2023-4573: Memory corruption in IPC CanvasTranslator Security Vulnerabilities fixed in Firefox 117 The system default sharing indicator will be used instead. Endpoint Detection & Response for Serversįirefox no longer shows its own screen sharing indicator on Wayland desktop environments.
0 Comments
Leave a Reply. |
AuthorWrite something about yourself. No need to be fancy, just an overview. ArchivesCategories |