Severity
8.8HIGHNVD
OSV6.5
EPSS
0.8%
top 26.71%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJan 23
Latest updateFeb 7

Description

The WebAudio `OscillatorNode` object was susceptible to a stack buffer overflow. This could have led to a potentially exploitable crash. This vulnerability affects Firefox < 122.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages3 packages

CVEListV5mozilla/firefoxunspecified122
NVDmozilla/firefox< 122.0
Ubuntumozilla/firefox< 122.0+build2-0ubuntu0.20.04.1+1

🔴Vulnerability Details

5
OSV
firefox regressions2024-02-07
OSV
firefox vulnerabilities2024-01-29
GHSA
GHSA-93gv-w5cx-phvx: The WebAudio `OscillatorNode` object was susceptible to a stack buffer overflow2024-01-23
OSV
CVE-2024-0745: The WebAudio `OscillatorNode` object was susceptible to a stack buffer overflow2024-01-23
CVEList
CVE-2024-0745: The WebAudio `OscillatorNode` object was susceptible to a stack buffer overflow2024-01-23

📋Vendor Advisories

6
Ubuntu
Firefox regressions2024-02-07
Ubuntu
Firefox vulnerabilities2024-01-29
Red Hat
firefox: stack buffer overflow in WebAudio `OscillatorNode`2024-01-23
Microsoft
The WebAudio `OscillatorNode` object was susceptible to a stack buffer overflow. This could have led to a potentially exploitable crash. This vulnerability affects Firefox < 122.2024-01-09
Debian
CVE-2024-0745: firefox - The WebAudio `OscillatorNode` object was susceptible to a stack buffer overflow....2024
CVE-2024-0745 — Out-of-bounds Write in Mozilla Firefox | cvebase