CVE-2024-2607 — Write-what-where Condition in Mozilla Firefox
Severity
8.1HIGHNVD
EPSS
1.5%
top 19.17%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMar 19
Latest updateMar 26
Description
Return registers were overwritten which could have allowed an attacker to execute arbitrary code. *Note:* This issue only affected Armv7-A systems. Other operating systems are unaffected. This vulnerability affects Firefox < 124, Firefox ESR < 115.9, and Thunderbird < 115.9.
CVSS vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 2.2 | Impact: 5.9
Affected Packages6 packages
Also affects: Debian Linux 10.0
🔴Vulnerability Details
4GHSA▶
GHSA-9xvp-gqgg-hh2x: Return registers were overwritten which could have allowed an attacker to execute arbitrary code↗2024-03-19
OSV▶
CVE-2024-2607: Return registers were overwritten which could have allowed an attacker to execute arbitrary code↗2024-03-19
CVEList▶
CVE-2024-2607: Return registers were overwritten which could have allowed an attacker to execute arbitrary code↗2024-03-19
📋Vendor Advisories
7Debian▶
CVE-2024-2607: firefox - Return registers were overwritten which could have allowed an attacker to execut...↗2024