Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2024-11691

Опубликовано: 26 нояб. 2024
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS3: 8.8

Описание

Certain WebGL operations on Apple silicon M series devices could have lead to an out-of-bounds write and memory corruption due to a flaw in Apple's GPU driver. This bug only affected the application on Apple M series hardware. Other platforms were unaffected. This vulnerability affects Firefox < 133, Firefox ESR < 128.5, Firefox ESR < 115.18, Thunderbird < 133, Thunderbird < 128.5, and Thunderbird < 115.18.

РелизСтатусПримечание
devel

not-affected

code not present
esm-infra/focal

DNE

focal

not-affected

MacOS only
jammy

not-affected

code not present
noble

not-affected

code not present
oracular

not-affected

code not present
upstream

not-affected

debian: Only affects Firefox on MacOS

Показывать по

РелизСтатусПримечание
devel

not-affected

code not present
esm-infra/focal

DNE

focal

released

1:115.18.0+build1-0ubuntu0.20.04.1
jammy

released

1:115.18.0+build1-0ubuntu0.22.04.1
noble

not-affected

code not present
oracular

not-affected

code not present
upstream

not-affected

debian: Only affects Thunderbird on MacOS

Показывать по

EPSS

Процентиль: 50%
0.00271
Низкий

8.8 High

CVSS3

Связанные уязвимости

CVSS3: 8.2
redhat
7 месяцев назад

Certain WebGL operations on Apple silicon M series devices could have lead to an out-of-bounds write and memory corruption due to a flaw in Apple's GPU driver. *This bug only affected the application on Apple M series hardware. Other platforms were unaffected.* This vulnerability affects Firefox < 133, Firefox ESR < 128.5, Firefox ESR < 115.18, Thunderbird < 133, Thunderbird < 128.5, and Thunderbird < 115.18.

CVSS3: 8.8
nvd
7 месяцев назад

Certain WebGL operations on Apple silicon M series devices could have lead to an out-of-bounds write and memory corruption due to a flaw in Apple's GPU driver. *This bug only affected the application on Apple M series hardware. Other platforms were unaffected.* This vulnerability affects Firefox < 133, Firefox ESR < 128.5, Firefox ESR < 115.18, Thunderbird < 133, Thunderbird < 128.5, and Thunderbird < 115.18.

CVSS3: 8.8
debian
7 месяцев назад

Certain WebGL operations on Apple silicon M series devices could have ...

CVSS3: 8.8
github
7 месяцев назад

An attacker could have caused memory corruption due to a flaw in Apple's GPU driver; this can be avoided by working around the flaw. *Note: This issue only affected macOS operating systems. Other operating systems are unaffected.* This vulnerability affects Firefox < 133, Firefox ESR < 128.5, Firefox ESR < 115.18, Thunderbird < 133, and Thunderbird < 128.5.

CVSS3: 8.8
fstec
7 месяцев назад

Уязвимость компонента Apple GPU Driver браузеров Mozilla Firefox, Firefox ESR и почтового клиента Thunderbird, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 50%
0.00271
Низкий

8.8 High

CVSS3