Memory Safety Bugs Affect Firefox and Thunderbird
CVE-2024-11699
8.8HIGH
Key Information:
- Vendor
Mozilla
- Vendor
- CVE Published:
- 26 November 2024
What is CVE-2024-11699?
A set of memory safety vulnerabilities in Mozilla's Firefox and Thunderbird products could potentially lead to memory corruption issues. Recent updates found evidence that these flaws could be exploited to execute arbitrary code under certain conditions. The affected versions include Firefox 132, Firefox ESR 128.4, and Thunderbird 128.4. Users are strongly encouraged to update to at least Firefox 133 and Thunderbird 133 to mitigate these risks.
Affected Version(s)
Firefox < 133
Firefox ESR < 128.5
Thunderbird < 133