cbcvebase.
CVE-2024-9394
published 2024-10-01

CVE-2024-9394: An attacker could, via a specially crafted multipart response, execute arbitrary JavaScript under the `resource://devtools` origin. This could allow them to…

high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
An attacker could, via a specially crafted multipart response, execute arbitrary JavaScript under the `resource://devtools` origin. This could allow them to access cross-origin JSON content. This access is limited to "same site" documents by the Site Isolation feature on desktop clients, but full cross-origin access is possible on Android versions. This vulnerability affects Firefox < 131, Firefox ESR < 128.3, Firefox ESR < 115.16, Thunderbird < 128.3, and Thunderbird < 131.

Affected

19 ranges
VendorProductVersion rangeFixed in
debianfirefox< firefox 131.0-1 (sid)firefox 131.0-1 (sid)
debianfirefox-esr< firefox 131.0-1 (sid)firefox 131.0-1 (sid)
debianthunderbird< firefox 131.0-1 (sid)firefox 131.0-1 (sid)
mozillafirefox< 131.0131.0
mozillafirefox
mozillafirefox>= 0 < 131.0+build1.1-0ubuntu0.20.04.1131.0+build1.1-0ubuntu0.20.04.1
mozillafirefox>= unspecified < 131131
mozillafirefox_esr< 115.16.0115.16.0
mozillafirefox_esr>= 116.0 < 128.3.0128.3.0
mozillafirefox_esr>= unspecified < 128.3128.3
mozillafirefox_esr>= unspecified < 115.16115.16
mozillathunderbird< 128.3128.3
mozillathunderbird
mozillathunderbird>= 0 < 1:115.16.0esr-1~deb11u11:115.16.0esr-1~deb11u1
mozillathunderbird>= 0 < 1:115.16.0esr-1~deb12u11:115.16.0esr-1~deb12u1
mozillathunderbird>= 0 < 1:128.3.0esr-11:128.3.0esr-1
mozillathunderbird>= 0 < 1:128.3.0esr-11:128.3.0esr-1
mozillathunderbird>= unspecified < 128.3128.3
mozillathunderbird>= unspecified < 131131

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
osv9.8CRITICAL