CVE-2023-5173: Mozilla Firefox
High severity, CVSS 7.5. EPSS: 0.9% chance of exploitation in the next 30 days.
In a non-standard configuration of Firefox, an integer overflow could have occurred based on network traffic (possibly under influence of a local unprivileged webpage), leading to an out-of-bounds write to privileged process memory. *This bug only affects Firefox if a non-standard preference allowing non-HTTPS Alternate Services (`network.http.altsvc.oe`) is enabled.* This vulnerability affects Firefox < 118.
Affected products
- Mozilla Firefox: before 118 (fixed in 118)
Published 2023-09-27. Last modified 2026-06-17.