CVE-2024-1556
Es bestehen mehrere Schwachstellen in Mozilla Firefox, Mozilla Firefox ESR und Mozilla Thunderbird. Diese Fehler bestehen in mehreren Funktionen und Modulen aufgrund mehrerer sicherheitsrelevanter Probleme, wie z. B. Lesen von Out-of-Bounds-Speicher, Cache Poisoning, ungültiger Speicherzugriff oder falsche Codegenerierung. Ein entfernter, anonymer Angreifer kann diese Schwachstellen ausnutzen, um beliebigen Code auszuführen, vertrauliche Informationen offenzulegen, Sicherheitsmaßnahmen zu umgehen oder einen nicht spezifizierten Angriff durchzuführen. Eine erfolgreiche Ausnutzung erfordert eine Benutzerinteraktion.
EPSS 0.37% · 59.4th percentile
Risk Scores
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Debian | Debian Linux | |
| Ubuntu | Ubuntu Linux | |
| SUSE | SUSE Linux | |
| IGEL | IGEL OS 11 | |
| Mozilla | Mozilla Firefox <123 | |
| RESF | RESF Rocky Linux | |
| Gentoo | Gentoo Linux | |
| Mozilla | Mozilla Thunderbird <115.8 | |
| Amazon | Amazon Linux 2 | |
| Red Hat | Red Hat Enterprise Linux | |
| Mozilla | Mozilla Firefox ESR <115.8 | |
| IGEL | IGEL OS 12 | |
| Fedora | Fedora Linux | |
| SUSE | SUSE openSUSE | |
| Oracle | Oracle Linux | |
| Open Source | Open Source CentOS |
Exploit Intelligence
Timeline
- Feb 20, 2024 CVE Published
- Feb 21, 2024 EPSS Score
- Mar 19, 2024 EPSS Score
- Apr 14, 2024 EPSS Score
- May 11, 2024 EPSS Score
- Jun 8, 2024 EPSS Score
- Jul 4, 2024 EPSS Score
- Jul 31, 2024 EPSS Score
- Aug 31, 2024 EPSS Score
- Oct 4, 2024 Coalition ESS Score
- Oct 23, 2024 EPSS Score
- Nov 12, 2024 CVE Updated
References
- https://wid.cert-bund.de/.well-known/csaf/white/2024/wid-sec-w-2024-0443.json advisory
- https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2024-0443 advisory
- https://www.mozilla.org/en-US/security/advisories/mfsa2024-05 advisory
- https://www.mozilla.org/en-US/security/advisories/mfsa2024-06 advisory
- https://www.mozilla.org/en-US/security/advisories/mfsa2024-07 advisory
- https://lists.debian.org/debian-security-announce/2024/msg00034.html advisory
- https://lists.suse.com/pipermail/sle-security-updates/2024-February/017979.html advisory
- https://ubuntu.com/security/notices/USN-6649-1 advisory
- https://bodhi.fedoraproject.org/updates/FEDORA-2024-81863a1613 advisory
- https://bodhi.fedoraproject.org/updates/FEDORA-2024-5361211b10 advisory
- https://access.redhat.com/errata/RHSA-2024:0952 advisory
- https://access.redhat.com/errata/RHSA-2024:0970 advisory
- https://linux.oracle.com/errata/ELSA-2024-0952.html advisory
- https://access.redhat.com/errata/RHSA-2024:0972 advisory
- https://access.redhat.com/errata/RHSA-2024:0955 advisory
- https://lists.debian.org/debian-security-announce/2024/msg00037.html advisory
- https://lists.suse.com/pipermail/sle-security-updates/2024-February/018005.html advisory
- https://lists.suse.com/pipermail/sle-security-updates/2024-February/018006.html advisory
- https://access.redhat.com/errata/RHSA-2024:0957 advisory
- https://access.redhat.com/errata/RHSA-2024:0958 advisory
…and 31 more