CVE-2024-8384

CVSS v3.1 9.8 (Critical)
98% Progress
EPSS 0.11 % (44th)
0.11% Progress
Affected Products 2
Advisories 14
NVD Status Modified

The JavaScript garbage collector could mis-color cross-compartment objects if OOM conditions were detected at the right point between two passes. This could have led to memory corruption. This vulnerability affects Firefox < 130, Firefox ESR < 128.2, Firefox ESR < 115.15, Thunderbird < 128.2, and Thunderbird < 115.15.

Weaknesses
CWE-416
Use After Free
CWE-787
Out-of-bounds Write
CVE Status
PUBLISHED
NVD Status
Modified
CNA
Mozilla Corporation
Published Date
2024-09-03 13:15:05
(13 days ago)
Updated Date
2024-09-06 17:15:17
(10 days ago)

Affected Products

Loading...
Loading...

Configuration #1

    CPE23 From Up To
  Mozilla Firefox prior 130.0 version cpe:2.3:a:mozilla:firefox < 130.0
  Mozilla Firefox Esr prior 115.15 version cpe:2.3:a:mozilla:firefox_esr < 115.15
  Mozilla Firefox Esr from 128.0 version and prior 128.2 version cpe:2.3:a:mozilla:firefox_esr >= 128.0 < 128.2
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...