CVE-2023-25737
CVSS 3.1 Score 8.8 of 10 (high)
Details
Published Jun 2, 2023
Updated: Jan 9, 2025
CWE ID 704
Summary
CVE-2023-25737 is a vulnerability affecting Firefox versions below 110, Thunderbird below 102.8, and Firefox ESR below 102.8. This issue involves an unvalidated downcast from an nsTextNode to an SVGElement, potentially resulting in undefined behavior. The downcast operation is not supposed to be applied to all types of nodes, leading to unexpected consequences when it is. This flaw could be exploited to execute arbitrary code or cause a denial-of-service condition. Users are advised to update their browsers to the latest versions to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.