CVE-2024-9936Race Condition in Mozilla Firefox

Severity
6.5MEDIUMNVD
EPSS
0.3%
top 45.71%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedOct 14
Latest updateOct 22

Description

When manipulating the selection node cache, an attacker may have been able to cause unexpected behavior, potentially leading to an exploitable crash. This vulnerability affects Firefox < 131.0.3.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:HExploitability: 2.8 | Impact: 3.6

Affected Packages3 packages

CVEListV5mozilla/firefoxunspecified131.0.3
NVDmozilla/firefox< 131.0.3
Ubuntumozilla/firefox< 131.0.3+build1-0ubuntu0.20.04.1

🔴Vulnerability Details

3
CVEList
CVE-2024-9936: When manipulating the selection node cache, an attacker may have been able to cause unexpected behavior, potentially leading to an exploitable crash2024-10-14
OSV
CVE-2024-9936: When manipulating the selection node cache, an attacker may have been able to cause unexpected behavior, potentially leading to an exploitable crash2024-10-14
GHSA
GHSA-8c7g-vx5g-cmpg: When manipulating the selection node cache, an attacker may have been able to cause unexpected behavior, potentially leading to an exploitable crash2024-10-14

📋Vendor Advisories

4
Ubuntu
Firefox vulnerability2024-10-22
Red Hat
firefox: Undefined behavior in selection node cache2024-10-14
Debian
CVE-2024-9936: firefox - When manipulating the selection node cache, an attacker may have been able to ca...2024
Mozilla
Mozilla Foundation Security Advisory 2024-53: CVE-2024-9936
CVE-2024-9936 — Race Condition in Mozilla Firefox | cvebase