CVE-2024-8381
published 2024-09-03CVE-2024-8381: A potentially exploitable type confusion could be triggered when looking up a property name on an object being used as the `with` environment. This…
critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
A potentially exploitable type confusion could be triggered when looking up a property name on an object being used as the `with` environment. This vulnerability affects Firefox < 130, Firefox ESR < 128.2, Firefox ESR < 115.15, Thunderbird < 128.2, and Thunderbird < 115.15.
Affected
20 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | firefox | < firefox 130.0-1 (sid) | firefox 130.0-1 (sid) |
| debian | firefox-esr | < firefox 130.0-1 (sid) | firefox 130.0-1 (sid) |
| debian | thunderbird | < firefox 130.0-1 (sid) | firefox 130.0-1 (sid) |
| mozilla | firefox | < 130.0 | 130.0 |
| mozilla | firefox | — | — |
| mozilla | firefox | >= 0 < 130.0+build2-0ubuntu0.20.04.1 | 130.0+build2-0ubuntu0.20.04.1 |
| mozilla | firefox | >= 0 < 130.0.1+build1-0ubuntu0.20.04.1 | 130.0.1+build1-0ubuntu0.20.04.1 |
| mozilla | firefox | >= unspecified < 130 | 130 |
| mozilla | firefox_esr | < 115.15 | 115.15 |
| mozilla | firefox_esr | >= 128.0 < 128.2 | 128.2 |
| mozilla | firefox_esr | >= unspecified < 128.2 | 128.2 |
| mozilla | firefox_esr | >= unspecified < 115.15 | 115.15 |
| mozilla | thunderbird | >= 0 < 1:115.15.0-1~deb11u1 | 1:115.15.0-1~deb11u1 |
| mozilla | thunderbird | >= 0 < 1:115.15.0-1~deb12u1 | 1:115.15.0-1~deb12u1 |
| mozilla | thunderbird | >= 0 < 1:128.2.0esr-1 | 1:128.2.0esr-1 |
| mozilla | thunderbird | >= 0 < 1:128.2.0esr-1 | 1:128.2.0esr-1 |
| mozilla | thunderbird | >= 0 < 1:115.15.0+build1-0ubuntu0.20.04.1 | 1:115.15.0+build1-0ubuntu0.20.04.1 |
| mozilla | thunderbird | >= 0 < 1:115.15.0+build1-0ubuntu0.22.04.1 | 1:115.15.0+build1-0ubuntu0.22.04.1 |
| mozilla | thunderbird | >= unspecified < 128.2 | 128.2 |
| mozilla | thunderbird | >= unspecified < 115.15 | 115.15 |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
osv9.8CRITICAL
Ubuntu
Firefox regressions
vendor_ubuntu·2024-09-23·CVSS 9.8
[CRITICAL] Firefox regressions
Title: Firefox regressions
Summary: USN-6992-1 caused some minor regressions in Firefox.
USN-6992-1 fixed vulnerabilities in Firefox. The update introduced
several minor regressions. This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
Multiple security issues were discovered in Firefox. If a user were
tricked into opening a specially crafted website, an attacker could
potentially exploit these to cause a denial of service, obtain sensitive
information across domains, or execute arbitrary code. (CVE-2024-8382,
CVE-2024-8383, CVE-2024-8386, CVE-2024-8387, CVE-2024-8389)
Nils Bars discovered that Firefox contained a type confusion vulnerability
when performing certain property name lookups. An attacker could
potentially exploit this issue to cau
Ubuntu
Thunderbird vulnerabilities
vendor_ubuntu·2024-09-09·CVSS 9.6
CVE-2024-7526 [CRITICAL] Thunderbird vulnerabilities
Title: Thunderbird vulnerabilities
Summary: Several security issues were fixed in Thunderbird.
Multiple security issues were discovered in Thunderbird. If a user were
tricked into opening a specially crafted website in a browsing context, an
attacker could potentially exploit these to cause a denial of service,
obtain sensitive information, bypass security restrictions, cross-site
tracing, or execute arbitrary code. (CVE-2024-7521, CVE-2024-7526,
CVE-2024-7527, CVE-2024-7529, CVE-2024-8382)
It was discovered that Thunderbird did not properly manage certain memory
operations when processing graphics shared memory. An attacker could
potentially exploit this issue to escape the sandbox. (CVE-2024-7519)
Irvan Kurniawan discovered that Thunderbird did not properly check an
attribute value i
Ubuntu
Firefox vulnerabilities
vendor_ubuntu·2024-09-05·CVSS 9.8
CVE-2024-8385 [CRITICAL] Firefox vulnerabilities
Title: Firefox vulnerabilities
Summary: Several security issues were fixed in Firefox.
Multiple security issues were discovered in Firefox. If a user were
tricked into opening a specially crafted website, an attacker could
potentially exploit these to cause a denial of service, obtain sensitive
information across domains, or execute arbitrary code. (CVE-2024-8382,
CVE-2024-8383, CVE-2024-8386, CVE-2024-8387, CVE-2024-8389)
Nils Bars discovered that Firefox contained a type confusion vulnerability
when performing certain property name lookups. An attacker could
potentially exploit this issue to cause a denial of service, or execute
arbitrary code. (CVE-2024-8381)
It was discovered that Firefox did not properly manage memory during
garbage collection. An attacker could potentially exploi
Red Hat
mozilla: Type confusion when looking up a property name in a "with" block
vendor_redhat·2024-09-03·CVSS 9.8
CVE-2024-8381 [CRITICAL] CWE-704 mozilla: Type confusion when looking up a property name in a "with" block
mozilla: Type confusion when looking up a property name in a "with" block
A potentially exploitable type confusion could be triggered when looking up a property name on an object being used as the `with` environment. This vulnerability affects Firefox < 130, Firefox ESR < 128.2, Firefox ESR < 115.15, Thunderbird < 128.2, and Thunderbird < 115.15.
The Mozilla Foundation's Security Advisory: A potentially exploitable type confusion could be triggered when looking up a property name on an object being used as the with environment.
Statement: Red Hat Product Security rates the severity of this flaw as determined by the Mozilla Foundation Security Advisory.
Package: firefox (Red Hat Enterprise Linux 6) - Out of support scope
Package: thunderbird (Red Hat Enterprise Linux 6) - Out of suppor
Debian
CVE-2024-8381: firefox - A potentially exploitable type confusion could be triggered when looking up a pr...
vendor_debian·2024·CVSS 9.8
CVE-2024-8381 [CRITICAL] CVE-2024-8381: firefox - A potentially exploitable type confusion could be triggered when looking up a pr...
A potentially exploitable type confusion could be triggered when looking up a property name on an object being used as the `with` environment. This vulnerability affects Firefox < 130, Firefox ESR < 128.2, Firefox ESR < 115.15, Thunderbird < 128.2, and Thunderbird < 115.15.
Scope: local
sid: resolved (fixed in 130.0-1)
Mozilla
Mozilla Foundation Security Advisory 2024-40: CVE-2024-8381
vendor_mozilla·CVSS 9.8
CVE-2024-8381 [CRITICAL] Mozilla Foundation Security Advisory 2024-40: CVE-2024-8381
Mozilla Foundation Security Advisory 2024-40
CVE: CVE-2024-8381
Product: Firefox ESR
Impact: high
Fixed in: Firefox ESR 128.2
Mozilla
Mozilla Foundation Security Advisory 2024-41: CVE-2024-8381
vendor_mozilla·CVSS 9.8
CVE-2024-8381 [CRITICAL] Mozilla Foundation Security Advisory 2024-41: CVE-2024-8381
Mozilla Foundation Security Advisory 2024-41
CVE: CVE-2024-8381
Product: Firefox ESR
Impact: moderate
Fixed in: Firefox ESR 115.15
Mozilla
Mozilla Foundation Security Advisory 2024-39: CVE-2024-8381
vendor_mozilla·CVSS 9.8
CVE-2024-8381 [CRITICAL] Mozilla Foundation Security Advisory 2024-39: CVE-2024-8381
Mozilla Foundation Security Advisory 2024-39
CVE: CVE-2024-8381
Product: Firefox
Impact: high
Fixed in: Firefox 130
Mozilla
Mozilla Foundation Security Advisory 2024-44: CVE-2024-8381
vendor_mozilla·CVSS 9.8
CVE-2024-8381 [CRITICAL] Mozilla Foundation Security Advisory 2024-44: CVE-2024-8381
Mozilla Foundation Security Advisory 2024-44
CVE: CVE-2024-8381
Product: Thunderbird
Impact: moderate
Fixed in: Thunderbird 115.15
Mozilla
Mozilla Foundation Security Advisory 2024-43: CVE-2024-8381
vendor_mozilla·CVSS 9.8
CVE-2024-8381 [CRITICAL] Mozilla Foundation Security Advisory 2024-43: CVE-2024-8381
Mozilla Foundation Security Advisory 2024-43
CVE: CVE-2024-8381
Product: Thunderbird
Impact: high
Fixed in: Thunderbird 128.2
OSV
firefox regressions
osv·2024-09-23·CVSS 9.8
CVE-2024-8382 [CRITICAL] firefox regressions
firefox regressions
USN-6992-1 fixed vulnerabilities in Firefox. The update introduced
several minor regressions. This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
Multiple security issues were discovered in Firefox. If a user were
tricked into opening a specially crafted website, an attacker could
potentially exploit these to cause a denial of service, obtain sensitive
information across domains, or execute arbitrary code. (CVE-2024-8382,
CVE-2024-8383, CVE-2024-8386, CVE-2024-8387, CVE-2024-8389)
Nils Bars discovered that Firefox contained a type confusion vulnerability
when performing certain property name lookups. An attacker could
potentially exploit this issue to cause a denial of service, or execute
arbitrary code. (CVE-2024-8381)
It
OSV
thunderbird vulnerabilities
osv·2024-09-09·CVSS 9.6
CVE-2024-7521 [CRITICAL] thunderbird vulnerabilities
thunderbird vulnerabilities
Multiple security issues were discovered in Thunderbird. If a user were
tricked into opening a specially crafted website in a browsing context, an
attacker could potentially exploit these to cause a denial of service,
obtain sensitive information, bypass security restrictions, cross-site
tracing, or execute arbitrary code. (CVE-2024-7521, CVE-2024-7526,
CVE-2024-7527, CVE-2024-7529, CVE-2024-8382)
It was discovered that Thunderbird did not properly manage certain memory
operations when processing graphics shared memory. An attacker could
potentially exploit this issue to escape the sandbox. (CVE-2024-7519)
Irvan Kurniawan discovered that Thunderbird did not properly check an
attribute value in the editor component, leading to an out-of-bounds read
vulnerabili
OSV
firefox vulnerabilities
osv·2024-09-05·CVSS 9.8
CVE-2024-8382 [CRITICAL] firefox vulnerabilities
firefox vulnerabilities
Multiple security issues were discovered in Firefox. If a user were
tricked into opening a specially crafted website, an attacker could
potentially exploit these to cause a denial of service, obtain sensitive
information across domains, or execute arbitrary code. (CVE-2024-8382,
CVE-2024-8383, CVE-2024-8386, CVE-2024-8387, CVE-2024-8389)
Nils Bars discovered that Firefox contained a type confusion vulnerability
when performing certain property name lookups. An attacker could
potentially exploit this issue to cause a denial of service, or execute
arbitrary code. (CVE-2024-8381)
It was discovered that Firefox did not properly manage memory during
garbage collection. An attacker could potentially exploit this issue to
cause a denial of service, or execute arbitrary
GHSA
GHSA-x565-97fv-jfr5: A potentially exploitable type confusion could be triggered when looking up a property name on an object being used as the `with` environment
ghsa_unreviewed·2024-09-03
CVE-2024-8381 [CRITICAL] CWE-843 GHSA-x565-97fv-jfr5: A potentially exploitable type confusion could be triggered when looking up a property name on an object being used as the `with` environment
A potentially exploitable type confusion could be triggered when looking up a property name on an object being used as the `with` environment. This vulnerability affects Firefox < 130, Firefox ESR < 128.2, and Firefox ESR < 115.15.
OSV
CVE-2024-8381: A potentially exploitable type confusion could be triggered when looking up a property name on an object being used as the `with` environment
osv·2024-09-03·CVSS 9.8
CVE-2024-8381 [CRITICAL] CVE-2024-8381: A potentially exploitable type confusion could be triggered when looking up a property name on an object being used as the `with` environment
A potentially exploitable type confusion could be triggered when looking up a property name on an object being used as the `with` environment. This vulnerability affects Firefox < 130, Firefox ESR < 128.2, Firefox ESR < 115.15, Thunderbird < 128.2, and Thunderbird < 115.15.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://bugzilla.mozilla.org/show_bug.cgi?id=1912715https://www.mozilla.org/security/advisories/mfsa2024-39/https://www.mozilla.org/security/advisories/mfsa2024-40/https://www.mozilla.org/security/advisories/mfsa2024-41/https://www.mozilla.org/security/advisories/mfsa2024-43/https://www.mozilla.org/security/advisories/mfsa2024-44/https://lists.debian.org/debian-lts-announce/2024/09/msg00012.htmlhttps://lists.debian.org/debian-lts-announce/2024/09/msg00025.html
2024-09-03
Published