CVE-2024-9680
קריטית 9.8 מנוצלת בשטח (KEV) בשימוש בכופרה
ניצול פעיל מאומת — קטלוג CISA KEV
- שם
- Mozilla Firefox Use-After-Free Vulnerability
- נוסף לקטלוג
- יעד טיפול (פדרלי)
- פעולה נדרשת
- Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
תיאור (מקור, אנגלית)
An attacker was able to achieve code execution in the content process by exploiting a use-after-free in Animation timelines. We have had reports of this vulnerability being exploited in the wild. This vulnerability affects Firefox < 131.0.2, Firefox ESR < 128.3.1, Firefox ESR < 115.16.1, Thunderbird < 131.0.1, Thunderbird < 128.3.1, and Thunderbird < 115.16.0.
מדדים
- CVSS 3.1
-
9.8 (CRITICAL)
מקור הציון: NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - EPSS — סבירות ניצול
- 23% (אחוזון 100) נכון ל-26/7/2026
- CWE
- CWE-416
מוצרים מושפעים
mozilla: firefox; mozilla: thunderbird; debian: debian linux
קישורים
- https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2024-49039 Not ApplicablePatchVendor Advisory
- https://www.mozilla.org/security/advisories/mfsa2024-51/ Vendor Advisory
- https://www.mozilla.org/security/advisories/mfsa2024-52/ Vendor Advisory
- https://bugzilla.mozilla.org/show_bug.cgi?id=1923344 Issue TrackingPermissions Required
- https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=281992 Issue Tracking
- https://lists.debian.org/debian-lts-announce/2024/10/msg00005.html Mailing List
- https://lists.debian.org/debian-lts-announce/2024/10/msg00006.html Mailing List
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-202… US Government Resource