Lucene search

K
cvelistMozillaCVELIST:CVE-2024-3864
HistoryApr 16, 2024 - 3:14 p.m.

CVE-2024-3864

2024-04-1615:14:09
mozilla
www.cve.org
1
memory safety
firefox
thunderbird
cve-2024-3864
vulnerability
exploitation
arbitrary code

6.6 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

10.3%

Memory safety bug present in Firefox 124, Firefox ESR 115.9, and Thunderbird 115.9. This bug showed evidence of memory corruption and we presume that with enough effort this could have been exploited to run arbitrary code. This vulnerability affects Firefox < 125, Firefox ESR < 115.10, and Thunderbird < 115.10.

CNA Affected

[
  {
    "product": "Firefox",
    "vendor": "Mozilla",
    "versions": [
      {
        "lessThan": "125",
        "status": "affected",
        "version": "unspecified",
        "versionType": "custom"
      }
    ]
  },
  {
    "product": "Firefox ESR",
    "vendor": "Mozilla",
    "versions": [
      {
        "lessThan": "115.10",
        "status": "affected",
        "version": "unspecified",
        "versionType": "custom"
      }
    ]
  },
  {
    "product": "Thunderbird",
    "vendor": "Mozilla",
    "versions": [
      {
        "lessThan": "115.10",
        "status": "affected",
        "version": "unspecified",
        "versionType": "custom"
      }
    ]
  }
]