cbcvebase.
CVE-2024-2605
published 2024-03-19

CVE-2024-2605: An attacker could have leveraged the Windows Error Reporter to run arbitrary code on the system escaping the sandbox. *Note:* This issue only affected Windows…

medium5.9CVSS 3.1
AVNACHPRNUINSUCNIHAN
An attacker could have leveraged the Windows Error Reporter to run arbitrary code on the system escaping the sandbox. *Note:* This issue only affected Windows operating systems. Other operating systems are unaffected. This vulnerability affects Firefox < 124, Firefox ESR < 115.9, and Thunderbird < 115.9.

Affected

11 ranges
VendorProductVersion rangeFixed in
debianfirefox
debianfirefox-esr
debianthunderbird
mozillafirefox< 115.9.0115.9.0
mozillafirefox< 124.0124.0
mozillafirefox
mozillafirefox>= unspecified < 124124
mozillafirefox_esr>= unspecified < 115.9115.9
mozillathunderbird< 115.9.0115.9.0
mozillathunderbird>= unspecified < 115.9115.9
msrcazl3_mozjs_102.15.1-1_on_azure_linux_3.0

CVSS provenance

nvdv3.15.9MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
osv5.9MEDIUM