CVE-2024-9680

Severity CVSS v4.0:
Pending analysis
Type:
CWE-416 Use After Free
Publication date:
09/10/2024
Last modified:
26/11/2024

Description

An attacker was able to achieve code execution in the content process by exploiting a use-after-free in Animation timelines. We have had reports of this vulnerability being exploited in the wild. This vulnerability affects Firefox

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:mozilla:firefox:*:*:*:*:esr:*:*:* 115.16.1 (excluding)
cpe:2.3:a:mozilla:firefox:*:*:*:*:-:*:*:* 131.0.2 (excluding)
cpe:2.3:a:mozilla:firefox:*:*:*:*:esr:*:*:* 128.1.0 (including) 128.3.1 (excluding)
cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:* 115.16.0 (excluding)
cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:* 128.0.1 (including) 128.3.1 (excluding)
cpe:2.3:a:mozilla:thunderbird:131.0:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*