[MFSA-2024-15] Security Vulnerabilities fixed in Firefox 124.0.1

Severity Critical
Affected Packages 1
Fixed Packages 1
CVEs 2
  • CVE-2024-29943: Out-of-bounds access via Range Analysis bypass (critical)
    An attacker was able to perform an out-of-bounds read or write on a JavaScript object by fooling range-based bounds check elimination.

  • CVE-2024-29944: Privileged JavaScript Execution via Event Handlers (critical)
    An attacker was able to inject an event handler into a privileged object that would allow arbitrary JavaScript execution in the parent process. <em>Note:</em> This vulnerability affects Desktop Firefox only, it does not affect mobile versions of Firefox.

Package Affected Version
pkg:mozilla/Firefox < 124.0.1
Package Fixed Version
pkg:mozilla/Firefox = 124.0.1
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:mozilla/Firefox Firefox < 124.0.1
Fixed pkg:mozilla/Firefox Firefox = 124.0.1
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date