An attacker was able to perform an out-of-bounds read or write on a JavaScript object by fooling range-based bounds check elimination. This vulnerability affects Firefox < 124.0.1.
CVSS Details
- CVSS 3.1 Base Score: 9.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Gentoo Linux | — | Upgrade www-client/firefox.Upgrade www-client/firefox-bin. | Jul 9, 2024 | Mar 22, 2024 |
| Mfsa2024 15 | — | Upgrade to Mozilla Firefox version 124.0.1Upgrade to the latest version of Mozilla Firefox | Mar 25, 2024 | Mar 22, 2024 |
| Ubuntu | — | Upgrade firefox | Mar 26, 2024 | Mar 22, 2024 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub