cbcvebase.
CVE-2024-8385
published 2024-09-03

CVE-2024-8385: A difference in the handling of StructFields and ArrayTypes in WASM could be used to trigger an exploitable type confusion vulnerability. This vulnerability…

critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
A difference in the handling of StructFields and ArrayTypes in WASM could be used to trigger an exploitable type confusion vulnerability. This vulnerability affects Firefox < 130, Firefox ESR < 128.2, and Thunderbird < 128.2.

Affected

12 ranges
VendorProductVersion rangeFixed in
debianfirefox< firefox 130.0-1 (sid)firefox 130.0-1 (sid)
debianthunderbird< firefox 130.0-1 (sid)firefox 130.0-1 (sid)
mozillafirefox< 130.0130.0
mozillafirefox
mozillafirefox>= 0 < 130.0+build2-0ubuntu0.20.04.1130.0+build2-0ubuntu0.20.04.1
mozillafirefox>= 0 < 130.0.1+build1-0ubuntu0.20.04.1130.0.1+build1-0ubuntu0.20.04.1
mozillafirefox>= unspecified < 130130
mozillafirefox_esr< 128.2128.2
mozillafirefox_esr>= unspecified < 128.2128.2
mozillathunderbird>= 0 < 1:128.2.0esr-11:128.2.0esr-1
mozillathunderbird>= 0 < 1:128.2.0esr-11:128.2.0esr-1
mozillathunderbird>= unspecified < 128.2128.2

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
osv9.8CRITICAL