CVE-2024-29943Out-of-bounds Read in Mozilla Firefox

Severity
9.8CRITICALNVD
EPSS
53.9%
top 1.99%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMar 22
Latest updateMay 19

Description

An attacker was able to perform an out-of-bounds read or write on a JavaScript object by fooling range-based bounds check elimination. This vulnerability affects Firefox < 124.0.1.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages3 packages

CVEListV5mozilla/firefoxunspecified124.0.1
NVDmozilla/firefox< 124.0.1
Ubuntumozilla/firefox< 124.0.2+build1-0ubuntu0.20.04.1+1

🔴Vulnerability Details

5
OSV
firefox regressions2024-04-04
OSV
firefox vulnerabilities2024-03-25
CVEList
CVE-2024-29943: An attacker was able to perform an out-of-bounds read or write on a JavaScript object by fooling range-based bounds check elimination2024-03-22
GHSA
GHSA-gv5g-5832-j3rm: An attacker was able to perform an out-of-bounds read or write on a JavaScript object by fooling range-based bounds check elimination2024-03-22
OSV
CVE-2024-29943: An attacker was able to perform an out-of-bounds read or write on a JavaScript object by fooling range-based bounds check elimination2024-03-22

📋Vendor Advisories

6
Ubuntu
Firefox regressions2024-04-04
Ubuntu
Firefox vulnerabilities2024-03-25
Red Hat
Mozilla: Out-of-bounds access via Range Analysis bypass2024-03-22
Microsoft
An attacker was able to perform an out-of-bounds read or write on a JavaScript object by fooling range-based bounds check elimination. This vulnerability affects Firefox < 124.0.1.2024-03-12
Debian
CVE-2024-29943: firefox - An attacker was able to perform an out-of-bounds read or write on a JavaScript o...2024

🕵️Threat Intelligence

3
Bleepingcomputer
Hackers earn $1,078,750 for 28 zero-days at Pwn2Own Berlin2025-05-19
Bleepingcomputer
Mozilla fixes Firefox zero-day actively exploited in attacks2024-10-09
Bleepingcomputer
Mozilla fixes two Firefox zero-day bugs exploited at Pwn2Own2024-03-22
CVE-2024-29943 — Out-of-bounds Read in Mozilla Firefox | cvebase