Lucene search

K
debiancveDebian Security Bug TrackerDEBIANCVE:CVE-2024-4771
HistoryMay 14, 2024 - 6:15 p.m.

CVE-2024-4771

2024-05-1418:15:14
Debian Security Bug Tracker
security-tracker.debian.org
14
memory allocation
use-after-free
firefox
vulnerability
code execution
unix

CVSS3

8.6

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H

AI Score

7.2

Confidence

Low

EPSS

0

Percentile

9.0%

A memory allocation check was missing which would lead to a use-after-free if the allocation failed. This could have triggered a crash or potentially be leveraged to achieve code execution. This vulnerability affects Firefox < 126.

OSVersionArchitecturePackageVersionFilename
Debian999allfirefox< 126.0-1firefox_126.0-1_all.deb

CVSS3

8.6

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H

AI Score

7.2

Confidence

Low

EPSS

0

Percentile

9.0%