A type confusion bug in WebAssembly could be leveraged by an attacker to potentially achieve code execution. This vulnerability affects Firefox < 129, Firefox ESR < 128.1, and Thunderbird < 128.1.
CVSS Details
- CVSS 3.1 Base Score: 8.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade thunderbirdUpgrade firefox-x11Upgrade firefox | Aug 22, 2024 | Aug 6, 2024 |
| Freebsd | — | Upgrade firefox | Aug 14, 2024 | Aug 13, 2024 |
| Gentoo Linux | — | Upgrade www-client/firefox-bin.Upgrade mail-client/thunderbird.Upgrade www-client/firefox.Upgrade dev-lang/spidermonkey.Upgrade mail-client/thunderbird-bin. | Dec 9, 2024 | Aug 6, 2024 |
| Mfsa2024 33 | — | Upgrade to Mozilla Firefox version 129.0 | Aug 7, 2024 | Aug 6, 2024 |
| Mfsa2024 35 | — | Upgrade to Mozilla Firefox ESR version 128.1 | Aug 7, 2024 | Aug 6, 2024 |
| Mozilla Thunderbird | — | Upgrade to Mozilla Thunderbird version 128.1 | Aug 7, 2024 | Aug 6, 2024 |
| Oracle_linux | — | Upgrade firefoxUpgrade firefox-x11Upgrade thunderbird | Oct 16, 2024 | Aug 6, 2024 |
| Redhat_linux | — | No solution existsUpgrade thunderbirdUpgrade thunderbird-debugsourceUpgrade firefox-x11Upgrade firefoxUpgrade thunderbird-debuginfoUpgrade firefox-debuginfoUpgrade firefox-debugsource | Aug 22, 2024 | Aug 6, 2024 |
| Rocky_linux | — | Upgrade thunderbirdUpgrade firefoxUpgrade firefox-debugsourceUpgrade thunderbird-debuginfoUpgrade firefox-debuginfoUpgrade thunderbird-debugsource | May 8, 2025 | Aug 6, 2024 |
| Suse | — | Upgrade mozillafirefox-translations-commonUpgrade mozillathunderbird-translations-commonUpgrade mozillafirefox-translations-otherUpgrade mozillathunderbirdUpgrade mozillafirefox-develUpgrade mozillathunderbird-translations-otherUpgrade mozillafirefoxUpgrade mozillafirefox-branding-sleUpgrade mozillafirefox-branding-upstream | Aug 14, 2024 | Aug 6, 2024 |
| Ubuntu | — | Upgrade firefox | Aug 20, 2024 | Aug 6, 2024 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub