CVE-2023-4578
Published: Sep 11, 2023
Modified: Dec 18, 2025
Description
When calling `JS::CheckRegExpSyntax` a Syntax Error could have been set which would end in calling `convertToRuntimeErrorAndClear`. A path in the function could attempt to allocate memory when none is available which would have caused a newly created Out of Memory exception to be mishandled as a Syntax Error. This vulnerability affects Firefox < 117, Firefox ESR < 115.2, and Thunderbird < 115.2.
| Vendor | Product | Versions |
|---|---|---|
Mozilla | Firefox | affected unspecified - < 117 |
Mozilla | Firefox ESR | affected unspecified - < 115.2 |
Mozilla | Thunderbird | affected unspecified - < 115.2 |
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now