VDB
CVE-2024-3863
CVE-2024-3863
PUBLISHED
In Mozilla Firefox, Mozilla Firefox ESR und Thunderbird existieren mehrere Schwachstellen. Die Ursachen sind unter anderem Out-of-Bounds read Probleme, Pufferüberläufe, unkontrollierter Ressourcen-Verbrauch, Use-After-Free Probleme und ungenügende Überprüfungen. Ein entfernter, anonymer Angreifer kann diese Schwachstellen ausnutzen, um Code auszuführen, Informationen offenzulegen, Sicherheitsmaßnahmen zu umgehen oder einen Denial of Service zu verursachen. Zur erfolgreichen Ausnutzung ist eine Benutzeraktion erforderlich.
EPSS 0.34% · 56.9th percentile
Risk Scores
EPSS Score
0.34%
56.9th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Oracle | Oracle Linux | |
| SUSE | SUSE openSUSE | |
| Xerox | Xerox FreeFlow Print Server v9 | |
| Red Hat | Red Hat Enterprise Linux | |
| Mozilla | Mozilla Firefox <125 | |
| Fedora | Fedora Linux | |
| Ubuntu | Ubuntu Linux | |
| Debian | Debian Linux | |
| Mozilla | Mozilla Thunderbird <115.10 | |
| IGEL | IGEL OS | |
| Gentoo | Gentoo Linux | |
| Amazon | Amazon Linux 2 | |
| Open Source | Open Source CentOS | |
| Mozilla | Mozilla Firefox ESR <115.10 | |
| RESF | RESF Rocky Linux | |
| SUSE | SUSE Linux |
Timeline
- Apr 16, 2024 CVE Published
- Apr 17, 2024 EPSS Score
- May 12, 2024 EPSS Score
- Jun 7, 2024 EPSS Score
- Jul 26, 2024 EPSS Score
- Aug 20, 2024 EPSS Score
- Sep 14, 2024 EPSS Score
- Oct 4, 2024 Coalition ESS Score
- Oct 9, 2024 EPSS Score
- Nov 3, 2024 EPSS Score
- Nov 28, 2024 EPSS Score
- Jan 17, 2025 EPSS Score
References
- https://wid.cert-bund.de/.well-known/csaf/white/2024/wid-sec-w-2024-0909.json advisory
- https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2024-0909 advisory
- https://www.mozilla.org/en-US/security/advisories/mfsa2024-18/ advisory
- https://www.mozilla.org/en-US/security/advisories/mfsa2024-19/ advisory
- https://lists.suse.com/pipermail/sle-security-updates/2024-April/018373.html advisory
- https://lists.debian.org/debian-security-announce/2024/msg00072.html advisory
- https://access.redhat.com/errata/RHSA-2024:1910 advisory
- https://access.redhat.com/errata/RHSA-2024:1909 advisory
- https://access.redhat.com/errata/RHSA-2024:1904 advisory
- https://access.redhat.com/errata/RHSA-2024:1905 advisory
- https://access.redhat.com/errata/RHSA-2024:1906 advisory
- https://access.redhat.com/errata/RHSA-2024:1907 advisory
- https://access.redhat.com/errata/RHSA-2024:1908 advisory
- https://access.redhat.com/errata/RHSA-2024:1911 advisory
- https://access.redhat.com/errata/RHSA-2024:1912 advisory
- https://linux.oracle.com/errata/ELSA-2024-1910.html advisory
- https://www.mozilla.org/en-US/security/advisories/mfsa2024-20/ advisory
- https://lists.suse.com/pipermail/sle-security-updates/2024-April/018382.html advisory
- https://linux.oracle.com/errata/ELSA-2024-1912.html advisory
- https://linux.oracle.com/errata/ELSA-2024-1908.html advisory
…and 35 more