Security Advisory – Multiple Vulnerabilities in Mozilla Products

Reference: CERTFR-2023-AVI-0881


  • Remote Arbitrary Code Execution
  • Remote Denial of Service
  • Security Policy Bypass
  • Data Confidentiality Breach
  • Remote Indirect Code Injection (XSS)
  • Unspecified by the Publisher

Affected Systems:

  • Firefox ESR versions prior to 115.4
  • Firefox versions prior to 119
  • Firefox for iOS versions prior to 119
  • Thunderbird versions prior to 115.4.1

Summary: Multiple vulnerabilities have been discovered in Mozilla products. Some of these vulnerabilities could allow an attacker to execute arbitrary code remotely, cause remote denial of service, bypass security policies, and compromise data confidentiality.

Recommendations: Users of affected Mozilla products are strongly advised to take the following actions:

  1. Update Mozilla Products: Ensure that Mozilla Firefox ESR, Firefox, Firefox for iOS, and Thunderbird are updated to the latest versions (115.4, 119, 119, and 115.4.1 or later, respectively).
  2. Refer to Security Bulletins: For detailed information and patches, refer to the official security bulletins released by Mozilla on October 24, 2023.


  1. Mozilla Security Advisory mfsa2023-47
  2. Mozilla Security Advisory mfsa2023-45
  3. Mozilla Security Advisory mfsa2023-46
  4. Mozilla Security Advisory mfsa2023-48

CVE References:

For a detailed version history and other related information, please refer to the official document’s version management section.