A type confusion bug in WebAssembly could be leveraged by an attacker to potentially achieve code execution. This vulnerability affects Firefox < 129, Firefox ESR < 128.1, and Thunderbird < 128.1.
CVSS Details
- CVSS 3.1 Base Score: 8.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade firefoxUpgrade thunderbirdUpgrade firefox-x11 | Aug 22, 2024 | Aug 6, 2024 |
| Freebsd | — | Upgrade firefox | Aug 14, 2024 | Aug 13, 2024 |
| Gentoo Linux | — | Upgrade www-client/firefox.Upgrade mail-client/thunderbird.Upgrade www-client/firefox-bin.Upgrade mail-client/thunderbird-bin.Upgrade dev-lang/spidermonkey. | Dec 9, 2024 | Aug 6, 2024 |
| Mfsa2024 33 | — | Upgrade to Mozilla Firefox version 129.0 | Aug 7, 2024 | Aug 6, 2024 |
| Mfsa2024 35 | — | Upgrade to Mozilla Firefox ESR version 128.1 | Aug 7, 2024 | Aug 6, 2024 |
| Mozilla Thunderbird | — | Upgrade to Mozilla Thunderbird version 128.1 | Aug 7, 2024 | Aug 6, 2024 |
| Oracle_linux | — | Upgrade firefox-x11Upgrade firefoxUpgrade thunderbird | Oct 16, 2024 | Aug 6, 2024 |
| Redhat_linux | — | Upgrade firefox-debugsourceUpgrade thunderbird-debuginfoUpgrade firefox-debuginfoNo solution existsUpgrade thunderbird-debugsourceUpgrade thunderbirdUpgrade firefoxUpgrade firefox-x11 | Aug 22, 2024 | Aug 6, 2024 |
| Rocky_linux | — | Upgrade firefox-debugsourceUpgrade firefoxUpgrade thunderbirdUpgrade thunderbird-debuginfoUpgrade thunderbird-debugsourceUpgrade firefox-debuginfo | May 8, 2025 | Aug 6, 2024 |
| Suse | — | Upgrade mozillafirefox-translations-commonUpgrade mozillathunderbird-translations-commonUpgrade mozillafirefox-translations-otherUpgrade mozillafirefox-develUpgrade mozillathunderbirdUpgrade mozillafirefox-branding-sleUpgrade mozillathunderbird-translations-otherUpgrade mozillafirefoxUpgrade mozillafirefox-branding-upstream | Aug 14, 2024 | Aug 6, 2024 |
| Ubuntu | — | Upgrade firefox | Aug 20, 2024 | Aug 6, 2024 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub