Medium severity6.5NVD Advisory· Published Jun 2, 2023· Updated Jun 17, 2026
CVE-2023-25741
CVE-2023-25741
Description
When dragging and dropping an image cross-origin, the image's size could potentially be leaked. This behavior was shipped in 109 and caused web compatibility problems as well as this security concern, so the behavior was disabled until further review. This vulnerability affects Firefox < 110.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
5cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*range: <110.0
- (no CPE)range: <110
- (no CPE)range: unspecified
- osv-coords2 versionspkg:rpm/opensuse/MozillaFirefox&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/firefox-esr&distro=openSUSE%20Tumbleweed
< 110.0.1-1.1+ 1 more
- (no CPE)range: < 110.0.1-1.1
- (no CPE)range: < 128.5.1-1.1
Patches
Vulnerability mechanics
References
4- bugzilla.mozilla.org/show_bug.cginvdExploitIssue TrackingVendor Advisory
- bugzilla.mozilla.org/show_bug.cginvdIssue TrackingVendor Advisory
- www.mozilla.org/security/advisories/mfsa2023-05/nvdVendor Advisory
- bugzilla.mozilla.org/show_bug.cginvdIssue TrackingPermissions Required
News mentions
0No linked articles in our index yet.