Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-29943

Опубликовано: 22 мар. 2024
Источник: redhat
CVSS3: 8.8
EPSS Средний

Описание

An attacker was able to perform an out-of-bounds read or write on a JavaScript object by fooling range-based bounds check elimination. This vulnerability affects Firefox < 124.0.1.

A flaw was found in Mozilla. The Mozilla Foundation Security Advisory describes this flaw as follows: An attacker was able to perform an out-of-bounds read or write on a JavaScript object by fooling range-based bounds check elimination.

Отчет

Red Hat Enterprise Linux ships Firefox Extended Support Release (ESR) and therefore it is not affected by this CVE.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6firefoxNot affected
Red Hat Enterprise Linux 7firefoxNot affected
Red Hat Enterprise Linux 8firefoxNot affected
Red Hat Enterprise Linux 9firefoxNot affected

Показывать по

Дополнительная информация

Статус:

Critical
Дефект:
CWE-125
Дефект:
CWE-787
https://bugzilla.redhat.com/show_bug.cgi?id=2271107Mozilla: Out-of-bounds access via Range Analysis bypass

EPSS

Процентиль: 98%
0.57368
Средний

8.8 High

CVSS3

Связанные уязвимости

CVSS3: 9.8
ubuntu
больше 1 года назад

An attacker was able to perform an out-of-bounds read or write on a JavaScript object by fooling range-based bounds check elimination. This vulnerability affects Firefox < 124.0.1.

CVSS3: 9.8
nvd
больше 1 года назад

An attacker was able to perform an out-of-bounds read or write on a JavaScript object by fooling range-based bounds check elimination. This vulnerability affects Firefox < 124.0.1.

msrc
3 месяца назад

An attacker was able to perform an out-of-bounds read or write on a JavaScript object by fooling range-based bounds check elimination. This vulnerability affects Firefox < 124.0.1.

CVSS3: 9.8
debian
больше 1 года назад

An attacker was able to perform an out-of-bounds read or write on a Ja ...

CVSS3: 9.8
github
больше 1 года назад

An attacker was able to perform an out-of-bounds read or write on a JavaScript object by fooling range-based bounds check elimination. This vulnerability affects Firefox < 124.0.1.

EPSS

Процентиль: 98%
0.57368
Средний

8.8 High

CVSS3

Уязвимость CVE-2024-29943