logo

Multiple Vulnerabilities in Mozilla Products Could Allow for Arbitrary Code Execution

ID: f2be83c2-b787-5947-b849-5a89dcbeb6b2

STIX ID: report--f2be83c2-b787-5947-b849-5a89dcbeb6b2

Feed Name: CISecurity.org Advisories

Threat Score
70/100

Date Published: 2024-09-25

Date Updated: 2026-04-27

...
...

Multiple critical and lower-severity vulnerabilities were disclosed in Mozilla products (Firefox and Thunderbird), including type confusion issues and memory-safety bugs (notably CVE-2024-8381, CVE-2024-8385, CVE-2024-8387, CVE-2024-8389) that could allow arbitrary code execution as the logged-on user; affected releases include Firefox 130, Firefox ESR 128.2, and Thunderbird 128.2, with several additional CVEs (CVE-2024-8382–8388) addressing lower-impact issues.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.