Open-Source Security Intelligence

Know every vulnerability
before it knows you.

DevGuard continuously monitors your dependencies and alerts you when CVEs like this one affect your stack — with real-time threat intelligence built for developers.

Search

NCSC-2024-0218

Published May 15, 2024·Last modified May 15, 2024
Description
Feiten

Mozilla heeft kwetsbaarheden verholpen in Firefox en Thunderbird

Interpretaties

Een kwaadwillende kan de kwetsbaarheden misbruiken om aanvallen uit te voeren die kunnen leiden tot de volgende categorieën schade:

  • Denial-of-Service (DoS)
  • Omzeilen van beveiligingsmaatregel
  • (Remote) code execution (Gebruikersrechten)
Oplossingen

Mozilla heeft updates uitgebracht om de kwetsbaarheden te verhelpen in Firefox 126, Firefox ESR 115.11 en Thunderbird 115.11. Voor meer informatie, zie bijgevoegde referenties.

Kans

medium

Schade

medium

CWE-120

Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')

CWE-212

Improper Removal of Sensitive Information Before Storage or Transfer

CWE-416

Use After Free

CWE-451

User Interface (UI) Misrepresentation of Critical Information

CWE-754

Improper Check for Unusual or Exceptional Conditions

CWE-829

Inclusion of Functionality from Untrusted Control Sphere

Scan your project

Continuously monitor your dependencies and get alerted when vulnerabilities like this one affect your stack.

Checkout DevGuard