Memory Safety Bugs Affecting Firefox and Thunderbird
CVE-2024-10467
8.8HIGH
Key Information:
- Vendor
Mozilla
- Vendor
- CVE Published:
- 29 October 2024
What is CVE-2024-10467?
This vulnerability arises from memory safety issues detected in specific versions of Firefox and Thunderbird. The identified bugs contain evidence of memory corruption, indicating the possibility of exploitation that could allow attackers to execute arbitrary code. The affected versions, including Firefox 131, Firefox ESR 128.3, and Thunderbird 128.3, expose users to risks if not updated to the latest versions, which address these vulnerabilities. Users are strongly advised to upgrade to Firefox 132, Firefox ESR 128.4, or Thunderbird 132 to mitigate the potential risks associated with these vulnerabilities.
Affected Version(s)
Firefox < 132
Firefox ESR < 128.4
Thunderbird < 128.4