cbcvebase.
CVE-2024-8381
published 2024-09-03

CVE-2024-8381: A potentially exploitable type confusion could be triggered when looking up a property name on an object being used as the `with` environment. This…

critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
A potentially exploitable type confusion could be triggered when looking up a property name on an object being used as the `with` environment. This vulnerability affects Firefox < 130, Firefox ESR < 128.2, Firefox ESR < 115.15, Thunderbird < 128.2, and Thunderbird < 115.15.

Affected

20 ranges
VendorProductVersion rangeFixed in
debianfirefox< firefox 130.0-1 (sid)firefox 130.0-1 (sid)
debianfirefox-esr< firefox 130.0-1 (sid)firefox 130.0-1 (sid)
debianthunderbird< firefox 130.0-1 (sid)firefox 130.0-1 (sid)
mozillafirefox< 130.0130.0
mozillafirefox
mozillafirefox>= 0 < 130.0+build2-0ubuntu0.20.04.1130.0+build2-0ubuntu0.20.04.1
mozillafirefox>= 0 < 130.0.1+build1-0ubuntu0.20.04.1130.0.1+build1-0ubuntu0.20.04.1
mozillafirefox>= unspecified < 130130
mozillafirefox_esr< 115.15115.15
mozillafirefox_esr>= 128.0 < 128.2128.2
mozillafirefox_esr>= unspecified < 128.2128.2
mozillafirefox_esr>= unspecified < 115.15115.15
mozillathunderbird>= 0 < 1:115.15.0-1~deb11u11:115.15.0-1~deb11u1
mozillathunderbird>= 0 < 1:115.15.0-1~deb12u11:115.15.0-1~deb12u1
mozillathunderbird>= 0 < 1:128.2.0esr-11:128.2.0esr-1
mozillathunderbird>= 0 < 1:128.2.0esr-11:128.2.0esr-1
mozillathunderbird>= 0 < 1:115.15.0+build1-0ubuntu0.20.04.11:115.15.0+build1-0ubuntu0.20.04.1
mozillathunderbird>= 0 < 1:115.15.0+build1-0ubuntu0.22.04.11:115.15.0+build1-0ubuntu0.22.04.1
mozillathunderbird>= unspecified < 128.2128.2
mozillathunderbird>= unspecified < 115.15115.15

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
osv9.8CRITICAL