Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2024-14974
HistoryMar 21, 2024 - 12:00 a.m.

Code execution vulnerability in multiple Mozilla products (CNVD-2024-14974)

2024-03-2100:00:00
China National Vulnerability Database
www.cnvd.org.cn
17
mozilla
firefox
thunderbird
windows error reporter
sandbox escape
arbitrary code
denial of service
vulnerability

AI Score

7.8

Confidence

High

EPSS

0

Percentile

15.5%

Mozilla Firefox is an open source web browser.Mozilla Firefox ESR is an extended support version of Firefox (the web browser).Mozilla Thunderbird is a suite of email client software separate from the Mozilla Application Suite. A code execution vulnerability exists in multiple Mozilla products that stems from the Windows Error Reporter being used as a sandbox escape vector. An attacker could exploit this vulnerability to execute arbitrary code or cause a denial of service on a vulnerable system.