CVE-2024-6604
Last modified
CVE-2024-6604 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. Memory safety bugs present in Firefox 127, Firefox ESR 115.12, and Thunderbird 115.12. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. EPSS estimates a 0.54% chance of exploitation in the next 30 days.
Description
Memory safety bugs present in Firefox 127, Firefox ESR 115.12, and Thunderbird 115.12. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 128, Firefox ESR < 115.13, Thunderbird < 115.13, and Thunderbird < 128.
Metrics
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Mozilla | Firefox | < 115.13 |
| Mozilla | Firefox | < 126.0 |
| Mozilla | Thunderbird | < 115.13 |
| Mozilla | Thunderbird | >= 116.0, < 128.0 |
References
- https://www.mozilla.org/security/advisories/mfsa2024-29/Vendor Advisory
- https://www.mozilla.org/security/advisories/mfsa2024-30/Vendor Advisory
- https://www.mozilla.org/security/advisories/mfsa2024-31/Vendor Advisory
- https://www.mozilla.org/security/advisories/mfsa2024-32/Vendor Advisory
- https://www.mozilla.org/security/advisories/mfsa2024-29/Vendor Advisory
- https://www.mozilla.org/security/advisories/mfsa2024-30/Vendor Advisory
- https://www.mozilla.org/security/advisories/mfsa2024-31/Vendor Advisory
- https://www.mozilla.org/security/advisories/mfsa2024-32/Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2024-6604?
How severe is CVE-2024-6604?
How do I fix CVE-2024-6604?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-6598A denial-of-service attack is possible through the execution…6.5
- CVE-2024-6599The Meks Video Importer plugin for WordPress is vulnerable t…4.3
- CVE-2024-6600Due to large allocation checks in Angle for GLSL shaders bei…6.3
- CVE-2024-6601A race condition could lead to a cross-origin container obta…4.7
- CVE-2024-6602A mismatch between allocator and deallocator could have led …9.8
- CVE-2024-6603In an out-of-memory scenario an allocation could fail but fr…7.4
- CVE-2024-6605Firefox Android allowed immediate interaction with permissio…8.8
- CVE-2024-6606Clipboard code failed to check the index on an array access.…8.2
- CVE-2024-6607It was possible to prevent a user from exiting pointerlock w…8.8
- CVE-2024-6608It was possible to move the cursor using pointerlock from an…4.3
- CVE-2024-6609When almost out-of-memory an elliptic curve key which was ne…8.8
- CVE-2024-6610Form validation popups could capture escape key presses. The…4.3
Are you affected by CVE-2024-6604?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
