Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:46535
HistoryApr 19, 2024 - 1:24 a.m.

Out-of-Bounds-Read

2024-04-1901:24:44
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
10
firefox
jit compiler
vulnerability
out-of-bounds-read
switch statements

8.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

6.3 Medium

AI Score

Confidence

Low

0.0004 Low

EPSS

Percentile

10.5%

firefox is vulnerable to Out-of-Bounds-Read. The vulnerability is due to incorrect optimization of switch statements by the JIT (Just-In-Time) compiler. It results in code with out-of-bounds-reads in certain code patterns involving switch statements.

8.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

6.3 Medium

AI Score

Confidence

Low

0.0004 Low

EPSS

Percentile

10.5%