CVE-2023-32214: Mozilla Firefox

High severity, CVSS 7.5. EPSS: 0.9% chance of exploitation in the next 30 days.

Protocol handlers `ms-cxh` and `ms-cxh-full` could have been leveraged to trigger a denial of service. *Note: This attack only affects Windows. Other operating systems are not affected.* This vulnerability affects Firefox < 113, Firefox ESR < 102.11, and Thunderbird < 102.11.

Affected products

  • Mozilla Firefox: before 113.0 (fixed in 113.0)
  • Mozilla Firefox ESR: before 102.11 (fixed in 102.11)
  • Mozilla Thunderbird: before 102.11 (fixed in 102.11)

Published 2023-06-19. Last modified 2026-06-17.