Vulnerability · NVD
CVE-2024-5700
HIGH 7.0
Memory safety bugs present in Firefox 126, Firefox ESR 115.11, and Thunderbird 115.11. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 127, Firefox ESR < 115.12, and Thunderbird < 115.12.
Attack vector : Local
No privileges required
Show raw CVSS vector
CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS
0.44%
exploit very unlikely
percentile 36.3%
Tracked apps referencing this CVE
For each app: the affected range, the fixing version, and where the tracked app stands today.
Vulnerable CPE configurations (1)
| Vendor | Product | Platform | Versions | CPE 2.3 URI |
|---|---|---|---|---|
| mozilla |
thunderbird All platforms (wildcard)
|
All platforms (wildcard) | <115.12 | cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:* |