CVE-2024-9403

Oct. 1, 2024, 7:35 p.m.

Received
CVE has been recently published to the CVE List and has been received by the NVD.

Products

Firefox

  • < 131

Thunderbird

  • < 131

Source

security@mozilla.org

Tags

CVE-2024-9403 details

Published : Oct. 1, 2024, 4:15 p.m.
Last Modified : Oct. 1, 2024, 7:35 p.m.

Description

Memory safety bugs present in Firefox 130. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 131 and Thunderbird < 131.

CVSS Score

1 2 3 4 5 6 7.3 8 9 10

Weakness

Weakness Name Description

CVSS Data

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

LOW

Base Score

7.3

Exploitability Score

3.9

Impact Score

3.4

Base Severity

HIGH

This website uses the NVD API, but is not approved or certified by it.