PT-2024-10428 · Mozilla+4 · Thunderbird+5
Tyson Smith
·
Published
2024-10-29
·
Updated
2026-02-02
·
CVE-2024-10468
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Firefox versions prior to 132
Thunderbird versions prior to 132
Description
The issue is related to potential race conditions in IndexedDB, which could cause memory corruption and lead to a potentially exploitable crash. This can be exploited by a remote attacker to cause a denial of service.
Recommendations
For Firefox versions prior to 132, update to version 132 or later to resolve the issue.
For Thunderbird versions prior to 132, update to version 132 or later to resolve the issue.
Fix
Allocation of Resources Without Limits
Race Condition
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Astra Linux
Firefox
Linuxmint
Thunderbird
Ubuntu