CVE-2024-9399
CVSS 3.1 Score 7.5 of 10 (high)
Details
Published Oct 1, 2024
Updated: Mar 14, 2025
CWE ID 404
Summary
CVE-2024-9399 is a newly disclosed vulnerability that can cause a denial of service (DoS) condition in Firefox versions below 131 and Firefox ESR below 128.3, as well as Thunderbird versions below 128.3 and 131. This issue arises when a website initiates a specifically designed WebTransport session, resulting in a Firefox process crash. This vulnerability poses a threat to users who access affected websites, potentially leading to an unintended disruption of service.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.