Lucene search

K
mozillaMozilla FoundationMFSA2024-15
HistoryMar 22, 2024 - 12:00 a.m.

Security Vulnerabilities fixed in Firefox 124.0.1 — Mozilla

2024-03-2200:00:00
Mozilla Foundation
www.mozilla.org
25
firefox
javascript
out-of-bounds
privilege escalation
desktop
vulnerability

6.4 Medium

AI Score

Confidence

High

0.0005 Low

EPSS

Percentile

16.2%

An attacker was able to perform an out-of-bounds read or write on a JavaScript object by fooling range-based bounds check elimination.
An attacker was able to inject an event handler into a privileged object that would allow arbitrary JavaScript execution in the parent process. Note: This vulnerability affects Desktop Firefox only, it does not affect mobile versions of Firefox.

Affected configurations

Vulners
Node
mozillafirefoxRange<124.0.1
CPENameOperatorVersion
firefoxlt124.0.1