Mozilla Patches Firefox Vulnerability Allowing Remote Code Execution, Sandbox Escape

Mozilla on Tuesday announced security updates for both Firefox and Thunderbird, to address 21 vulnerabilities, including several memory safety issues.
Firefox 121 was released with patches for 18 vulnerabilities, five of which have a 'high' severity rating.
At the top of the list is CVE-2023-6856, a heap buffer overflow bug in WebGL, the JavaScript API for rendering interactive graphics within the browser.
Next in line is CVE-2023-6135, an issue rendering Network Security Services NIST curves vulnerable to the Minerva side-channel attack, which could allow adversaries to recover the long-term private key.
Mozilla also resolved CVE-2023-6865, a bug potentially exposing uninitialized data in EncryptingOutputStream, which could be exploited to write data to a local disk, potentially impacting the private browsing mode.
The latest Firefox iteration also addresses multiple memory safety issues that are collectively tracked as CVE-2023-6873 and CVE-2023-6864.
The latter also impacts Firefox ESR and Thunderbird.
Firefox 121 also resolves eight medium-severity flaws, including heap buffer overflow, use-after-free, and sandbox escape issues.
The remaining five bugs are rated 'low' severity.
On Tuesday, Mozilla announced the release of Thunderbird 115.6 with patches for 11 vulnerabilities, nine of which were addressed in Firefox as well.
The remaining two, both high-severity flaws, could allow attackers to spoof email messages, or spoof the time at which a message was sent.
Firefox ESR 115.6 was also released on Tuesday, with patches for 11 of the security defects that Firefox 121 resolves.
Mozilla makes no mention of any of these vulnerabilities being exploited in attacks.
Additional information can be found on Mozilla's security advisories page.


This Cyber News was published on www.securityweek.com. Publication date: Wed, 20 Dec 2023 15:43:05 +0000


Cyber News related to Mozilla Patches Firefox Vulnerability Allowing Remote Code Execution, Sandbox Escape

What is a Sandbox? Definition from SearchSecurity - A sandbox is an isolated testing environment that enables users to run programs or open files without affecting the application, system or platform on which they run. Using a sandbox to detect malware offers an additional layer of protection against ...
1 year ago Techtarget.com
Mozilla Patches Firefox Vulnerability Allowing Remote Code Execution, Sandbox Escape - Mozilla on Tuesday announced security updates for both Firefox and Thunderbird, to address 21 vulnerabilities, including several memory safety issues. Firefox 121 was released with patches for 18 vulnerabilities, five of which have a 'high' severity ...
1 year ago Securityweek.com CVE-2023-6856 CVE-2023-6135 CVE-2023-6865 CVE-2023-6873 CVE-2023-6864
Mozilla warns Windows users of critical Firefox sandbox escape flaw - In October, Mozilla also patched a zero-day vulnerability (CVE-2024-9680) in Firefox's animation timeline feature exploited by the Russian-based RomCom cybercrime group that let the attackers gain code execution in the web browser's sandbox. ...
2 months ago Bleepingcomputer.com CVE-2024-9680
MirrorFace APT Hackers Exploited Windows Sandbox & Visual Studio Code Using Custom Malware - The campaign, attributed to a threat actor known as “MirrorFace,” a subgroup operating under the APT10 umbrella, exploited Windows Sandbox and Visual Studio Code to execute malicious activities while evading detection from security tools ...
3 months ago Cybersecuritynews.com APT1
Mozilla warns users to update Firefox before certificate expires - Mozilla is warning Firefox users to update their browsers to the latest version to avoid facing disruption and security risks caused by the upcoming expiration of one of the company's root certificates. "On 14 March a root certificate (the ...
3 months ago Bleepingcomputer.com
5 Best Ways a Malware Sandbox Can Help Your Company - Malware sandboxes are indispensable for threat analysis, but many of their capabilities are often overlooked. Malware sandboxes equipped with advanced AI capabilities can significantly enhance the training and productivity of junior security staff. ...
1 year ago Cybersecuritynews.com
Google Adds V8 Sandbox To Chrome To Fight Against Browser Attacks - A Sandbox is a protective medium that blocks the entire system from any application accessing vulnerable resources. Restrictive environments for web content in browsers called sandboxes reduce the impact that can be caused by browser-based attacks ...
1 year ago Gbhackers.com
Protecting User Privacy by Removing Personal Data from Data Broker Sites - As part of its new subscription service model, Mozilla Firefox is offering its users the possibility of finding and removing their personal and sensitive information from data brokers across the internet. To eliminate their phone numbers, e-mail, ...
1 year ago Cysecurity.news
Mozilla Urging Users to Update Firefox, Else Add-ons Will Stop Working - The company stated in its support documentation that “not updating Firefox before the root certificate expires can expose you to significant security threats. iOS users are not impacted due to Firefox on Apple’s mobile platform utilizing ...
3 months ago Cybersecuritynews.com
New ISC Security Patches Released for 2021: What You Need to Know - The Internet Systems Consortium (ISC), the largest provider of open-source Internet infrastructure software, has released new security patches designed to mitigate data breaches and other cyber threats. These new security patches, released in January ...
2 years ago Thehackernews.com
CVE-2006-1733 - Mozilla Firefox and Thunderbird 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0 does not properly protect the compilation scope of privileged built-in XBL bindings, which allows remote attackers to execute ...
6 years ago
Firefox 137 Released With Fix for Multiple High Severity Vulnerabilities - This critical security update, announced on April 1, 2025, fixes several memory safety bugs and use-after-free vulnerabilities that posed significant risks to users of previous versions. The fixes in Firefox 137 and Thunderbird 137 included hardening ...
2 months ago Cybersecuritynews.com
GitLab Patches: Severe SAML Authentication Bypass Flaw Fixed - Security Boulevard - In addition to these patches, OmniAuth SAML has been upgraded to version 2.2.1 and Ruby-SAML to 1.17.0. It’s worth mentioning that the issue only impacts self-managed instances; therefore, users of GitLab Dedicated instances do not need to take any ...
8 months ago Securityboulevard.com CVE-2024-45409
CVE-2006-1732 - Unspecified vulnerability in Mozilla Firefox and Thunderbird 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0 allows remote attackers to bypass same-origin protections and conduct cross-site scripting (XSS) ...
6 years ago
5 Must-Have Tools for Effective Dynamic Malware Analysis - After launching the executable file found inside the archive, the sandbox instantly detects that the system has been infected with AsyncRAT, a popular malware family used by attackers to remotely control victims' machines and steal sensitive data. ...
8 months ago Thehackernews.com
Mozilla Firefox's Premium Dark Web Monitoring Solution - Mozilla, renowned for its commitment to an open and secure internet, has recently made a strategic foray into unexplored realms with the introduction of a subscription-based dark web monitoring service. This bold move signifies the organization's ...
1 year ago Cysecurity.news
CVE-2024-49360 - Sandboxie is a sandbox-based isolation software for 32-bit and 64-bit Windows NT-based operating systems. An authenticated user (**UserA**) with no privileges is authorized to read all files created in sandbox belonging to other users in the sandbox ...
6 months ago
Mozilla adds paid-for data-deletion tier to Monitor service The Register - Mozilla on Tuesday expanded its free privacy-monitoring service with a paid-for tier called Mozilla Monitor Plus that will try to get data brokers to delete their copies of subscribers' personal information. Mozilla introduced Monitor in 2018 as a ...
1 year ago Go.theregister.com
Oracle Security Update - Patch for 378 Vulnerabilities Including Remote Exploits - “Oracle strongly recommends that customers remain on actively-supported versions and apply Critical Patch Update security patches without delay,” the company stated in its advisory. Oracle Database Server versions 19.3-19.26, 21.3-21.17, ...
2 months ago Cybersecuritynews.com
Firefox 138 Released With Fix for Multiple High-severity Vulnerabilities - “By injecting code into the user-privileged process, an attacker could bypass intended access controls, allowing SYSTEM-level file operations on paths controlled by a non-privileged user and enabling privilege escalation,” Mozilla ...
1 month ago Cybersecuritynews.com CVE-2025-4083
Firefox continues Manifest V2 support as Chrome disables MV2 ad-blockers - Firefox has not stated how long this support will continue, but as long as there are powerful add-ons enhancing user privacy and security, Mozilla should continue to have strong reasons to extend support for Manifest V2. The latest announcement ...
3 months ago Bleepingcomputer.com
Mozilla Faces GDPR Complaint Over New Firefox Tracking Feature - NOYB, a European privacy group has filed a complaint with Austrian authorities, alleging that Mozilla breached GDPR by enabling “Privacy Preserving Attribution” (PPA), a tracking feature in Firefox, by default without user consent. The ...
8 months ago Hackread.com
CVE-2021-21261 - Flatpak is a system for building, distributing, and running sandboxed desktop applications on Linux. A bug was discovered in the `flatpak-portal` service that can allow sandboxed applications to execute arbitrary code on the host system (a sandbox ...
4 years ago
Mozilla Releases Urgent Patch for Windows Users Following Recently Exploited Chrome Zero-day - While Mozilla has not confirmed whether the Firefox vulnerability was exploited in the wild, the advisory notes that the “original vulnerability was being exploited in the wild,” likely referring to the Chrome zero-day. Mozilla researcher ...
2 months ago Cybersecuritynews.com
Google Chrome Vulnerability Let Attackers Escape Payload from Sandbox - Technical Details Disclosed - A critical vulnerability in Google Chrome has recently been discovered that allows malicious actors to break out of the browser’s protective sandbox environment, potentially giving attackers access to the underlying operating system. This ...
1 month ago Cybersecuritynews.com