CVE-2024-9396

It is currently unknown if this issue is exploitable but a condition may arise where the structured clone of certain objects could lead to memory corruption. This vulnerability affects Firefox < 131, Firefox ESR < 128.3, Thunderbird < 128.3, and Thunderbird < 131.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:mozilla:firefox:*:*:*:*:esr:*:*:*
cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*

History

04 Apr 2025, 14:39

Type Values Removed Values Added
CPE cpe:2.3:a:mozilla:firefox:*:*:*:*:esr:*:*:*
cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*
First Time Mozilla firefox
Mozilla thunderbird
Mozilla
References () https://bugzilla.mozilla.org/show_bug.cgi?id=1912471 - () https://bugzilla.mozilla.org/show_bug.cgi?id=1912471 - Issue Tracking
References () https://www.mozilla.org/security/advisories/mfsa2024-46/ - () https://www.mozilla.org/security/advisories/mfsa2024-46/ - Vendor Advisory
References () https://www.mozilla.org/security/advisories/mfsa2024-47/ - () https://www.mozilla.org/security/advisories/mfsa2024-47/ - Vendor Advisory
References () https://www.mozilla.org/security/advisories/mfsa2024-49/ - () https://www.mozilla.org/security/advisories/mfsa2024-49/ - Vendor Advisory
References () https://www.mozilla.org/security/advisories/mfsa2024-50/ - () https://www.mozilla.org/security/advisories/mfsa2024-50/ - Vendor Advisory

04 Oct 2024, 13:51

Type Values Removed Values Added
Summary
  • (es) Actualmente se desconoce si este problema se puede explotar, pero puede darse el caso de que la clonación estructurada de determinados objetos pueda provocar daños en la memoria. Esta vulnerabilidad afecta a Firefox &lt; 131, Firefox ESR &lt; 128.3, Thunderbird &lt; 128.3 y Thunderbird &lt; 131.

01 Oct 2024, 20:35

Type Values Removed Values Added
CWE CWE-119
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.8

01 Oct 2024, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-10-01 16:15

Updated : 2025-04-04 14:39


NVD link : CVE-2024-9396

Mitre link : CVE-2024-9396

CVE.ORG link : CVE-2024-9396


JSON object : View

Products Affected

mozilla

  • thunderbird
  • firefox
CWE
CWE-119

Improper Restriction of Operations within the Bounds of a Memory Buffer