VDB

GCVE-110-NCSC-2024-387

GCVE-110-NCSC-2024-387
Advisory PublishedCVSS 7.5/10
Vulnetix · Advisory published October 2, 2024
Mozilla heeft kwetsbaarheden verholpen in Firefox en Thunderbird.

Weaknesses (CWE)

CWE-451User Interface (UI) Misrepresentation of Critical InformationCWE-346Origin Validation ErrorCWE-94Improper Control of Generation of Code ('Code Injection')CWE-1021Improper Restriction of Rendered UI Layers or FramesCWE-119Improper Restriction of Operations within the Bounds of a Memory Buffer

Risk Scores

CVSS 3.1
7.5/10
High · CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Affected Products

VendorProductVersionsPlatforms
mozillafirefox_esr
mozillafirefox
mozillathunderbird

References

advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory

Browse GCVE Records

74,198 records in the GCVE database · Updated July 21, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›