cbcvebase.
CVE-2024-7526
published 2024-08-06

CVE-2024-7526: ANGLE failed to initialize parameters which lead to reading from uninitialized memory. This could be leveraged to leak sensitive data from memory. This…

medium6.5CVSS 3.1
AVNACLPRNUIRSUCHINAN
ANGLE failed to initialize parameters which lead to reading from uninitialized memory. This could be leveraged to leak sensitive data from memory. This vulnerability affects Firefox < 129, Firefox ESR < 115.14, Firefox ESR < 128.1, Thunderbird < 128.1, and Thunderbird < 115.14.

Affected

22 ranges
VendorProductVersion rangeFixed in
debianfirefox< firefox 129.0-1 (sid)firefox 129.0-1 (sid)
debianfirefox-esr< firefox 129.0-1 (sid)firefox 129.0-1 (sid)
debianthunderbird< firefox 129.0-1 (sid)firefox 129.0-1 (sid)
mozillafirefox< 129.0129.0
mozillafirefox
mozillafirefox>= 0 < 129.0.2+build1-0ubuntu0.20.04.1129.0.2+build1-0ubuntu0.20.04.1
mozillafirefox>= 0 < 129.0.1+build1-0ubuntu0.20.04.1129.0.1+build1-0ubuntu0.20.04.1
mozillafirefox>= unspecified < 129129
mozillafirefox_esr< 115.14.0115.14.0
mozillafirefox_esr
mozillafirefox_esr>= unspecified < 115.14115.14
mozillafirefox_esr>= unspecified < 128.1128.1
mozillathunderbird< 115.14.0115.14.0
mozillathunderbird
mozillathunderbird>= 0 < 1:115.14.0-1~deb11u11:115.14.0-1~deb11u1
mozillathunderbird>= 0 < 1:115.14.0-1~deb12u11:115.14.0-1~deb12u1
mozillathunderbird>= 0 < 1:128.1.0esr-11:128.1.0esr-1
mozillathunderbird>= 0 < 1:128.1.0esr-11:128.1.0esr-1
mozillathunderbird>= 0 < 1:115.15.0+build1-0ubuntu0.20.04.11:115.15.0+build1-0ubuntu0.20.04.1
mozillathunderbird>= 0 < 1:115.15.0+build1-0ubuntu0.22.04.11:115.15.0+build1-0ubuntu0.22.04.1
mozillathunderbird>= unspecified < 128.1128.1
mozillathunderbird>= unspecified < 115.14115.14

CVSS provenance

nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
osv9.6CRITICAL