CVE-2024-9400

CVSS 3.1 Score 8.8 of 10 (high)

Details

Published Oct 1, 2024
Updated: Oct 4, 2024
CWE ID 119

Summary

CVE-2024-9400 is a memory corruption vulnerability that affects Firefox versions below 131, Firefox ESR below 128.3, Thunderbird versions below 128.3, and Thunderbird versions below 131. If an attacker successfully triggers an Out-of-Memory (OOM) condition during Just-In-Time (JIT) compilation, they could potentially exploit this vulnerability. This issue could lead to arbitrary code execution, resulting in significant security implications for affected users. It is strongly recommended that users update their Firefox and Thunderbird browsers to their latest versions to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Mozilla Thunderbird
  • Mozilla Firefox

Affected Vendors

  • Mozilla