CVE-2024-1546 — Out-of-bounds Read in Mozilla Firefox
Severity
7.5HIGHNVD
EPSS
0.5%
top 34.06%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedFeb 20
Latest updateMar 6
Description
When storing and re-accessing data on a networking channel, the length of buffers may have been confused, resulting in an out-of-bounds memory read. This vulnerability affects Firefox < 123, Firefox ESR < 115.8, and Thunderbird < 115.8.
CVSS vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 1.6 | Impact: 5.9
Affected Packages6 packages
Also affects: Debian Linux 10.0
🔴Vulnerability Details
6CVEList▶
CVE-2024-1546: When storing and re-accessing data on a networking channel, the length of buffers may have been confused, resulting in an out-of-bounds memory read↗2024-02-20
GHSA▶
GHSA-w267-2gcr-ggcp: When storing and re-accessing data on a networking channel, the length of buffers may have been confused, resulting in an out-of-bounds memory read↗2024-02-20
📋Vendor Advisories
7Debian▶
CVE-2024-1546: firefox - When storing and re-accessing data on a networking channel, the length of buffer...↗2024