[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"repo-stars":3,"vuln-CVE-2023-5174":6},{"stargazers_count":4,"fetched_at":5},5,"2026-04-05T15:10:51.567Z",{"id":7,"descriptions":8,"cisa":9,"weaknesses":10,"exploits":20,"aliases":21,"duplicate_of":9,"upstream":22,"downstream":23,"duplicates":40,"related":41,"reserved_at":9,"published_at":49,"modified_at":50,"state":51,"summary":52,"references_raw":61,"kevs":81,"epss":82,"epss_history":85,"metrics":354,"affected":361},"CVE-2023-5174","If Windows failed to duplicate a handle during process creation, the sandbox code may have inadvertently freed a pointer twice, resulting in a use-after-free and a potentially exploitable crash.\n*This bug only affects Firefox on Windows when run in non-standard configurations (such as using `runas`). Other operating systems are unaffected.* This vulnerability affects Firefox \u003C 118, Firefox ESR \u003C 115.3, and Thunderbird \u003C 115.3.",null,[11],{"_key":12,"id":12,"name":13,"description":14,"type":15,"status":16,"abstraction":17,"likelihood_of_exploit":18,"capec":19},"CWE-416","Use After Free","The product reuses or references memory after it has been freed. At some point afterward, the memory may be allocated again and saved in another pointer, while the original pointer references a location somewhere within the new allocation. Any operations using the original pointer are no longer valid because the memory \"belongs\" to the code that operates on the new pointer.","weakness","Stable","Variant","High",[],[],[],[],[24,26,28,30,32,34,36,38],{"_key":25},"SUSE-SU-2023:3837-1",{"_key":27},"UBUNTU-CVE-2023-5174",{"_key":29},"SUSE-SU-2023:3899-1",{"_key":31},"SUSE-SU-2023:3898-1",{"_key":33},"SUSE-SU-2023:4016-1",{"_key":35},"OPENSUSE-SU-2024:13268-1",{"_key":37},"OPENSUSE-SU-2024:13272-1",{"_key":39},"OPENSUSE-SU-2024:14572-1",[],[42,43,44,45,46,47,48],{"_key":25},{"_key":29},{"_key":31},{"_key":33},{"_key":35},{"_key":37},{"_key":39},"2023-09-27T14:13:19.990Z","2025-05-05T14:59:34.904Z","Modified",{"cisa_kev":53,"cisa_ransomware":53,"cisa_vendor":9,"epss_severity":54,"epss_score":55,"severity":56,"severity_score":57,"severity_version":58,"severity_source":59,"severity_vector":60,"severity_status":51},false,"low",0.00445,"critical",9.8,"v3.1","cve.org","CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",[62,68,73,77],{"url":63,"sources":64,"tags":66},"https://bugzilla.mozilla.org/show_bug.cgi?id=1848454",[59,65],"nvd",[67],"Permissions Required",{"url":69,"sources":70,"tags":71},"https://www.mozilla.org/security/advisories/mfsa2023-41/",[59,65],[72],"Vendor Advisory",{"url":74,"sources":75,"tags":76},"https://www.mozilla.org/security/advisories/mfsa2023-42/",[59,65],[72],{"url":78,"sources":79,"tags":80},"https://www.mozilla.org/security/advisories/mfsa2023-43/",[59,65],[72],[],{"date":83,"score":55,"percentile":84},"2026-04-05",0.63402,[86,90,93,96,99,102,105,108,111,114,117,120,123,126,128,132,135,138,140,143,146,149,152,155,158,161,164,167,170,173,176,179,182,185,188,191,194,197,200,203,206,209,212,215,218,221,224,227,230,233,236,240,243,246,249,252,255,258,261,264,267,270,273,276,279,282,285,288,290,293,296,299,302,305,308,311,314,317,319,322,325,328,331,334,337,339,342,345,348,351],{"date":87,"score":88,"percentile":89},"2025-11-04",0.00281,0.51086,{"date":91,"score":88,"percentile":92},"2025-11-05",0.51068,{"date":94,"score":88,"percentile":95},"2025-11-06",0.51085,{"date":97,"score":88,"percentile":98},"2025-11-07",0.51108,{"date":100,"score":88,"percentile":101},"2025-11-08",0.51113,{"date":103,"score":88,"percentile":104},"2025-11-09",0.51103,{"date":106,"score":88,"percentile":107},"2025-11-10",0.51072,{"date":109,"score":88,"percentile":110},"2025-11-11",0.5109,{"date":112,"score":88,"percentile":113},"2025-11-12",0.51114,{"date":115,"score":88,"percentile":116},"2025-11-13",0.51116,{"date":118,"score":88,"percentile":119},"2025-11-14",0.51122,{"date":121,"score":88,"percentile":122},"2025-11-15",0.51115,{"date":124,"score":88,"percentile":125},"2025-11-16",0.51094,{"date":127,"score":88,"percentile":107},"2025-11-17",{"date":129,"score":130,"percentile":131},"2025-11-18",0.00923,0.74021,{"date":133,"score":130,"percentile":134},"2025-11-19",0.74027,{"date":136,"score":130,"percentile":137},"2025-11-20",0.74038,{"date":139,"score":88,"percentile":95},"2025-11-21",{"date":141,"score":88,"percentile":142},"2025-11-22",0.5108,{"date":144,"score":88,"percentile":145},"2025-11-23",0.51042,{"date":147,"score":88,"percentile":148},"2025-11-24",0.51035,{"date":150,"score":88,"percentile":151},"2025-11-25",0.51043,{"date":153,"score":88,"percentile":154},"2025-11-26",0.51044,{"date":156,"score":88,"percentile":157},"2025-11-27",0.5105,{"date":159,"score":88,"percentile":160},"2025-11-28",0.51014,{"date":162,"score":88,"percentile":163},"2025-11-29",0.50994,{"date":165,"score":88,"percentile":166},"2025-11-30",0.50983,{"date":168,"score":88,"percentile":169},"2025-12-01",0.51132,{"date":171,"score":88,"percentile":172},"2025-12-02",0.51154,{"date":174,"score":88,"percentile":175},"2025-12-03",0.51152,{"date":177,"score":88,"percentile":178},"2025-12-04",0.50999,{"date":180,"score":88,"percentile":181},"2025-12-05",0.51024,{"date":183,"score":88,"percentile":184},"2025-12-06",0.51023,{"date":186,"score":88,"percentile":187},"2025-12-07",0.51016,{"date":189,"score":88,"percentile":190},"2025-12-08",0.5102,{"date":192,"score":88,"percentile":193},"2025-12-09",0.51041,{"date":195,"score":88,"percentile":196},"2025-12-10",0.51106,{"date":198,"score":88,"percentile":199},"2025-12-11",0.51124,{"date":201,"score":88,"percentile":202},"2025-12-12",0.51156,{"date":204,"score":88,"percentile":205},"2025-12-13",0.51143,{"date":207,"score":88,"percentile":208},"2025-12-14",0.51128,{"date":210,"score":88,"percentile":211},"2025-12-15",0.51107,{"date":213,"score":88,"percentile":214},"2025-12-16",0.51118,{"date":216,"score":88,"percentile":217},"2025-12-17",0.5114,{"date":219,"score":88,"percentile":220},"2025-12-18",0.51176,{"date":222,"score":88,"percentile":223},"2025-12-19",0.51179,{"date":225,"score":88,"percentile":226},"2025-12-20",0.51145,{"date":228,"score":88,"percentile":229},"2025-12-21",0.5112,{"date":231,"score":88,"percentile":232},"2025-12-22",0.51099,{"date":234,"score":88,"percentile":235},"2025-12-23",0.511,{"date":237,"score":238,"percentile":239},"2025-12-24",0.00367,0.58037,{"date":241,"score":238,"percentile":242},"2025-12-25",0.58084,{"date":244,"score":238,"percentile":245},"2025-12-26",0.58081,{"date":247,"score":238,"percentile":248},"2025-12-27",0.58137,{"date":250,"score":238,"percentile":251},"2025-12-28",0.58055,{"date":253,"score":238,"percentile":254},"2025-12-29",0.58045,{"date":256,"score":238,"percentile":257},"2025-12-30",0.58048,{"date":259,"score":238,"percentile":260},"2025-12-31",0.58086,{"date":262,"score":238,"percentile":263},"2026-01-01",0.58256,{"date":265,"score":238,"percentile":266},"2026-01-02",0.58239,{"date":268,"score":238,"percentile":269},"2026-01-03",0.58235,{"date":271,"score":238,"percentile":272},"2026-01-04",0.58056,{"date":274,"score":238,"percentile":275},"2026-01-05",0.58047,{"date":277,"score":238,"percentile":278},"2026-01-06",0.58058,{"date":280,"score":238,"percentile":281},"2026-01-07",0.58087,{"date":283,"score":238,"percentile":284},"2026-01-08",0.58109,{"date":286,"score":238,"percentile":287},"2026-01-09",0.58113,{"date":289,"score":238,"percentile":287},"2026-01-10",{"date":291,"score":55,"percentile":292},"2026-01-11",0.62859,{"date":294,"score":55,"percentile":295},"2026-01-12",0.62839,{"date":297,"score":55,"percentile":298},"2026-01-13",0.62834,{"date":300,"score":55,"percentile":301},"2026-01-14",0.62877,{"date":303,"score":55,"percentile":304},"2026-01-15",0.62894,{"date":306,"score":55,"percentile":307},"2026-01-16",0.62914,{"date":309,"score":55,"percentile":310},"2026-01-17",0.62907,{"date":312,"score":55,"percentile":313},"2026-01-18",0.62905,{"date":315,"score":55,"percentile":316},"2026-01-19",0.62891,{"date":318,"score":55,"percentile":310},"2026-01-20",{"date":320,"score":55,"percentile":321},"2026-01-21",0.62909,{"date":323,"score":55,"percentile":324},"2026-01-22",0.62913,{"date":326,"score":55,"percentile":327},"2026-01-23",0.62946,{"date":329,"score":55,"percentile":330},"2026-01-24",0.62952,{"date":332,"score":55,"percentile":333},"2026-01-25",0.62918,{"date":335,"score":55,"percentile":336},"2026-01-26",0.62908,{"date":338,"score":55,"percentile":307},"2026-01-27",{"date":340,"score":55,"percentile":341},"2026-01-28",0.62927,{"date":343,"score":55,"percentile":344},"2026-01-29",0.62921,{"date":346,"score":55,"percentile":347},"2026-01-30",0.62928,{"date":349,"score":55,"percentile":350},"2026-01-31",0.62932,{"date":352,"score":55,"percentile":353},"2026-02-01",0.63073,[355,359],{"source":59,"cvss_v2_0":9,"cvss_v3_0":9,"cvss_v3_1":356,"cvss_v4_0":9},{"baseScore":57,"baseSeverity":357,"vectorString":60,"impactScore":57,"exploitabilityScore":358},"CRITICAL",10,{"source":65,"cvss_v2_0":9,"cvss_v3_0":9,"cvss_v3_1":360,"cvss_v4_0":9},{"baseScore":57,"baseSeverity":357,"vectorString":60,"impactScore":57,"exploitabilityScore":358},[362,375,386],{"ecosystem":9,"name":363,"vendor":9,"product":363,"cpe_part":9,"purl_type":9,"purl_namespace":9,"purl_name":9,"source":9,"versions":364},"Firefox",[365,372],{"version":366,"is_range":367,"range_type":59,"version_start":368,"version_start_type":369,"version_end":370,"version_end_type":371,"fixed_in":9},">= unspecified, \u003C 118",true,"unspecified","including","118","excluding",{"version":373,"is_range":367,"range_type":374,"version_start":9,"version_start_type":9,"version_end":370,"version_end_type":371,"fixed_in":9},"lt118","cpe",{"ecosystem":9,"name":376,"vendor":377,"product":378,"cpe_part":379,"purl_type":9,"purl_namespace":9,"purl_name":9,"source":9,"versions":380},"Firefox ESR","mozilla","firefox esr","a",[381,384],{"version":382,"is_range":367,"range_type":59,"version_start":368,"version_start_type":369,"version_end":383,"version_end_type":371,"fixed_in":9},">= unspecified, \u003C 115.3","115.3",{"version":385,"is_range":367,"range_type":374,"version_start":9,"version_start_type":9,"version_end":383,"version_end_type":371,"fixed_in":9},"lt115.3",{"ecosystem":9,"name":387,"vendor":377,"product":387,"cpe_part":379,"purl_type":9,"purl_namespace":9,"purl_name":9,"source":9,"versions":388},"thunderbird",[389,390],{"version":382,"is_range":367,"range_type":59,"version_start":368,"version_start_type":369,"version_end":383,"version_end_type":371,"fixed_in":9},{"version":385,"is_range":367,"range_type":374,"version_start":9,"version_start_type":9,"version_end":383,"version_end_type":371,"fixed_in":9}]