CVE-2024-11704
CVSS 3.1 Score 9.8 of 10 (high)
Details
Published Nov 26, 2024
Updated: Nov 27, 2024
CWE ID 415
Summary
CVE-2024-11704 is a newly identified vulnerability affecting Firefox versions below 133 and Thunderbird versions below 133. The issue stems from a double-free condition in the `sec_pkcs7_decoder_start_decrypt()` function. When handling specific error paths, the symmetric key associated with the data being decrypted could be freed twice. Memory corruption is a potential consequence of this double-free incident.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Mozilla Thunderbird
- Mozilla Firefox
Affected Vendors
- Mozilla