[MFSA-2024-15] Security Vulnerabilities fixed in Firefox 124.0.1
Severity
Critical
Affected Packages
1
Fixed Packages
1
CVEs
2
CVE-2024-29943: Out-of-bounds access via Range Analysis bypass (critical)
An attacker was able to perform an out-of-bounds read or write on a JavaScript object by fooling range-based bounds check elimination.CVE-2024-29944: Privileged JavaScript Execution via Event Handlers (critical)
An attacker was able to inject an event handler into a privileged object that would allow arbitrary JavaScript execution in the parent process. <em>Note:</em> This vulnerability affects Desktop Firefox only, it does not affect mobile versions of Firefox.
Package | Affected Version |
---|---|
pkg:mozilla/Firefox | < 124.0.1 |
Package | Fixed Version |
---|---|
pkg:mozilla/Firefox | = 124.0.1 |
- ID
- MFSA-2024-15
- Severity
- critical
- URL
- https://www.mozilla.org/en-US/security/advisories/mfsa2024-15
- Published
-
2024-03-22T00:00:00
(6 months ago) - Modified
-
2024-03-22T00:00:00
(6 months ago) - Other Advisories
Source | # ID | Name | URL |
---|---|---|---|
Bugzilla | 1886849 | https://bugzilla.mozilla.org/show_bug.cgi?id=1886849 | |
Bugzilla | 1886852 | https://bugzilla.mozilla.org/show_bug.cgi?id=1886852 |
# CVE | Description | CVSS | EPSS | EPSS Trend (30 days) | Affected Products | Weaknesses | Security Advisories | Exploits | PoC | Pubblication Date | Modification Date |
---|---|---|---|---|---|---|---|---|---|---|---|
# CVE | Description | CVSS | EPSS | EPSS Trend (30 days) | Affected Products | Weaknesses | Security Advisories | PoC | Pubblication Date | Modification Date |