CVE-2023-25739
CVSS 3.1 Score 8.8 of 10 (high)
Details
Published Jun 2, 2023
Updated: Jan 9, 2025
CWE ID 416
Summary
CVE-2023-25739 is a vulnerability affecting Firefox versions prior to 110, Thunderbird versions under 102.8, and Firefox ESR versions under 102.8. This issue arises from a failure to check if module load requests have been cancelled, leading to a use-after-free condition within the <code>ScriptLoadContext</code> component. Consequently, an attacker could potentially exploit this vulnerability by loading malicious scripts, potentially resulting in arbitrary code execution.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.