Memory Management Issue in Firefox and Thunderbird by Mozilla
CVE-2024-6609
8.8HIGH
What is CVE-2024-6609?
A memory management vulnerability exists in Firefox and Thunderbird where an unallocated elliptic curve key could be improperly freed when the system is nearly out of memory. This issue may lead to unexpected behavior in the affected software, creating potential security risks for users. Affected versions include Firefox and Thunderbird prior to version 128. Users of these products should ensure they are updated to mitigate the risks associated with this vulnerability.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Firefox < 128
Thunderbird < 128
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published