Mozilla · Firefox Esr · CVE-2024-9680
**Name of the Vulnerable Software and Affected Versions**
Mozilla Firefox versions 128.3.1 ESR through 131.0.2
Mozilla Thunderbird versions 128.3.1 through 128.4.2
**Description**
The reported issue addresses a use-after-free vulnerability in Mozilla Firefox and Thunderbird. This vulnerability could potentially allow for arbitrary code execution. The issue affects versions 128.3.1 ESR and later of Firefox, and versions 128.3.1 and later of Thunderbird. Multiple security issues were discovered in both applications.
**Recommendations**
Mozilla Firefox versions 128.3.1 ESR through 131.0.2: Upgrade to the latest version.
Mozilla Thunderbird versions 128.3.1 through 128.4.2: Upgrade to the latest version.