CVE-2024-8385

CVSS v3.1 9.8 (Critical)
98% Progress
EPSS 0.07 % (31th)
0.07% Progress
Affected Products 2
Advisories 7
NVD Status Modified

A difference in the handling of StructFields and ArrayTypes in WASM could be used to trigger an exploitable type confusion vulnerability. This vulnerability affects Firefox < 130, Firefox ESR < 128.2, and Thunderbird < 128.2.

Weaknesses
CWE-843
Access of Resource Using Incompatible Type ('Type Confusion')
CVE Status
PUBLISHED
NVD Status
Modified
CNA
Mozilla Corporation
Published Date
2024-09-03 13:15:05
(13 days ago)
Updated Date
2024-09-06 17:15:17
(10 days ago)

Affected Products

Loading...
Loading...

Configuration #1

    CPE23 From Up To
  Mozilla Firefox prior 130.0 version cpe:2.3:a:mozilla:firefox < 130.0
  Mozilla Firefox Esr prior 128.2 version cpe:2.3:a:mozilla:firefox_esr < 128.2
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...