← All CVEs

CVE-2023-6856

high · 8.8

The WebGL `DrawElementsInstanced` method was susceptible to a heap buffer overflow when used on systems with the Mesa VM driver. This issue could allow an attacker to perform remote code execution and sandbox escape. This vulnerability affects Firefox ESR < 115.6, Thunderbird < 115.6, and Firefox < 121.

8.8
CVSS
20.6%
EPSS (exploit prob.)
97th
EPSS percentile
2023-12-19
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Weaknesses

CWE-787

Affected products

VendorProductAffected versions
mozillafirefox< 121.0
mozillafirefox_esr< 115.6
mozillathunderbird< 115.6
debiandebian_linux10.0
debiandebian_linux11.0
debiandebian_linux12.0

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2023-6856