Lucene search

K
ubuntucveUbuntu.comUB:CVE-2024-3864
HistoryApr 16, 2024 - 12:00 a.m.

CVE-2024-3864

2024-04-1600:00:00
ubuntu.com
ubuntu.com
9
memory safety bug
firefox 124
esr 115.9
thunderbird 115.9
memory corruption
arbitrary code execution
vulnerability
firefox<125
esr<115.10
mozilla
ubuntu

6.2 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

10.3%

Memory safety bug present in Firefox 124, Firefox ESR 115.9, and
Thunderbird 115.9. This bug showed evidence of memory corruption and we
presume that with enough effort this could have been exploited to run
arbitrary code. This vulnerability affects Firefox < 125, Firefox ESR <
115.10, and Thunderbird < 115.10.

Notes

Author Note
tyhicks mozjs contains a copy of the SpiderMonkey JavaScript engine
mdeslaur starting with Ubuntu 22.04, the firefox package is just a script that installs the Firefox snap