CVE-2024-5696Out-of-bounds Write in Mozilla Firefox

Severity
8.6HIGHNVD
OSV8.1
EPSS
2.1%
top 16.03%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 11
Latest updateJul 3

Description

By manipulating the text in an ` ` tag, an attacker could have caused corrupt memory leading to a potentially exploitable crash. This vulnerability affects Firefox < 127, Firefox ESR < 115.12, and Thunderbird < 115.12.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:HExploitability: 3.9 | Impact: 4.7

Affected Packages7 packages

CVEListV5mozilla/firefoxunspecified127
NVDmozilla/firefox< 115.12+1
CVEListV5mozilla/firefox_esrunspecified115.12
CVEListV5mozilla/thunderbirdunspecified115.12
NVDmozilla/thunderbird< 115.12

Also affects: Debian Linux 10.0

🔴Vulnerability Details

4
OSV
thunderbird vulnerabilities2024-06-19
CVEList
CVE-2024-5696: By manipulating the text in an ` ` tag, an attacker could have caused corrupt memory leading to a potentially exploitable crash2024-06-11
OSV
CVE-2024-5696: By manipulating the text in an ` ` tag, an attacker could have caused corrupt memory leading to a potentially exploitable crash2024-06-11
GHSA
GHSA-gmgg-93h8-cp32: By manipulating the text in an ` ` tag, an attacker could have caused corrupt memory leading to a potentially exploitable crash2024-06-11

📋Vendor Advisories

7
Ubuntu
Firefox vulnerabilities2024-07-03
Ubuntu
Thunderbird vulnerabilities2024-06-19
Red Hat
Mozilla: Memory Corruption in Text Fragments2024-06-11
Debian
CVE-2024-5696: firefox - By manipulating the text in an `&lt;input&gt;` tag, an attacker could have cause...2024
Mozilla
Mozilla Foundation Security Advisory 2024-26: CVE-2024-5696
CVE-2024-5696 — Out-of-bounds Write in Mozilla Firefox | cvebase