Описание
An attacker was able to perform an out-of-bounds read or write on a JavaScript object by confusing array index sizes. This vulnerability affects Firefox < 138.0.4, Firefox ESR < 128.10.1, Firefox ESR < 115.23.1, Thunderbird < 128.10.2, and Thunderbird < 138.0.2.
| Релиз | Статус | Примечание | 
|---|---|---|
| devel | not-affected  | code not present | 
| esm-infra/focal | DNE  | |
| focal | ignored  | end of standard support, was needed | 
| jammy | not-affected  | code not present | 
| noble | not-affected  | code not present | 
| oracular | not-affected  | code not present | 
| plucky | not-affected  | code not present | 
| questing | not-affected  | code not present | 
| upstream | needs-triage  | 
Показывать по
| Релиз | Статус | Примечание | 
|---|---|---|
| devel | DNE  | |
| esm-apps/noble | ignored  | |
| esm-infra/focal | DNE  | |
| focal | DNE  | |
| jammy | ignored  | |
| noble | ignored  | |
| oracular | DNE  | |
| plucky | DNE  | |
| questing | DNE  | |
| upstream | needs-triage  | 
Показывать по
| Релиз | Статус | Примечание | 
|---|---|---|
| devel | DNE  | |
| esm-infra/focal | DNE  | |
| focal | DNE  | |
| jammy | DNE  | |
| noble | ignored  | |
| oracular | ignored  | |
| plucky | ignored  | |
| questing | DNE  | |
| upstream | needs-triage  | 
Показывать по
| Релиз | Статус | Примечание | 
|---|---|---|
| devel | DNE  | |
| esm-apps/bionic | needs-triage  | |
| esm-infra/focal | DNE  | |
| focal | DNE  | |
| jammy | DNE  | |
| noble | DNE  | |
| oracular | DNE  | |
| plucky | DNE  | |
| questing | DNE  | |
| upstream | needs-triage  | 
Показывать по
| Релиз | Статус | Примечание | 
|---|---|---|
| devel | DNE  | |
| esm-apps/focal | needs-triage  | |
| esm-infra/bionic | ignored  | |
| focal | ignored  | |
| jammy | DNE  | |
| noble | DNE  | |
| oracular | DNE  | |
| plucky | DNE  | |
| questing | DNE  | |
| upstream | needs-triage  | 
Показывать по
| Релиз | Статус | Примечание | 
|---|---|---|
| devel | DNE  | |
| esm-infra/focal | ignored  | |
| focal | ignored  | |
| jammy | DNE  | |
| noble | DNE  | |
| oracular | DNE  | |
| plucky | DNE  | |
| questing | DNE  | |
| upstream | needs-triage  | 
Показывать по
| Релиз | Статус | Примечание | 
|---|---|---|
| devel | DNE  | |
| esm-apps/jammy | needs-triage  | |
| esm-infra/focal | DNE  | |
| focal | DNE  | |
| jammy | ignored  | |
| noble | DNE  | |
| oracular | DNE  | |
| plucky | DNE  | |
| questing | DNE  | |
| upstream | needs-triage  | 
Показывать по
| Релиз | Статус | Примечание | 
|---|---|---|
| devel | DNE  | |
| esm-infra/focal | DNE  | |
| focal | DNE  | |
| jammy | ignored  | |
| noble | DNE  | |
| oracular | DNE  | |
| plucky | DNE  | |
| questing | DNE  | |
| upstream | needs-triage  | 
Показывать по
| Релиз | Статус | Примечание | 
|---|---|---|
| devel | not-affected  | code not present | 
| esm-infra/focal | DNE  | |
| focal | ignored  | end of standard support, was needed | 
| jammy | released  | 1:128.12.0+build1-0ubuntu0.22.04.1 | 
| noble | not-affected  | code not present | 
| oracular | not-affected  | code not present | 
| plucky | not-affected  | code not present | 
| questing | not-affected  | code not present | 
| upstream | released  | 128.10.2 | 
Показывать по
Ссылки на источники
EPSS
8.8 High
CVSS3
Связанные уязвимости
An attacker was able to perform an out-of-bounds read or write on a JavaScript object by confusing array index sizes. This vulnerability affects Firefox < 138.0.4, Firefox ESR < 128.10.1, Firefox ESR < 115.23.1, Thunderbird < 128.10.2, and Thunderbird < 138.0.2.
An attacker was able to perform an out-of-bounds read or write on a JavaScript object by confusing array index sizes. This vulnerability affects Firefox < 138.0.4, Firefox ESR < 128.10.1, Firefox ESR < 115.23.1, Thunderbird < 128.10.2, and Thunderbird < 138.0.2.
An attacker was able to perform an out-of-bounds read or write on a Ja ...
An attacker was able to perform an out-of-bounds read or write on a JavaScript object by confusing array index sizes. This vulnerability affects Firefox ESR < 115.23.1.
Уязвимость браузеров Mozilla Firefox, Firefox ESR и почтового клиента Thunderbird, связанная с записью за границами буфера в памяти, позволяющая нарушителю выполнить произвольный код
EPSS
8.8 High
CVSS3