Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:46532
HistoryApr 19, 2024 - 1:24 a.m.

Use-After-Free

2024-04-1901:24:09
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
9
firefox
use-after-free
vulnerability
javascript realm
garbage collection

7.5 High

CVSS3

Attack Vector

ADJACENT

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

6.6 Medium

AI Score

Confidence

Low

0.0004 Low

EPSS

Percentile

9.0%

Firefox vulnerable to a use-after-free vulnerability. The vulnerability is due to improper handling where a use-after-free could occur if a JavaScript realm was being initialized when garbage collection started.

7.5 High

CVSS3

Attack Vector

ADJACENT

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

6.6 Medium

AI Score

Confidence

Low

0.0004 Low

EPSS

Percentile

9.0%