CVE-2024-10466: SQL Injection
By sending a specially crafted push message, a remote server could have hung the parent process, causing the browser to become unresponsive.
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2024-10466?
CVE-2024-10466 is classified as a high-severity vulnerability due to its potential to cause a denial of service.
How do I fix CVE-2024-10466?
To fix CVE-2024-10466, update to the latest version of Mozilla Thunderbird or Firefox beyond the specified vulnerable versions.
Which versions are affected by CVE-2024-10466?
CVE-2024-10466 affects Mozilla Thunderbird and Firefox versions up to and including 132, as well as Firefox ESR versions up to and including 128.4.
What impact does CVE-2024-10466 have on users?
CVE-2024-10466 can cause the browser to become unresponsive if a specially crafted push message is received.
Who is affected by CVE-2024-10466?
Users of Mozilla Thunderbird and Mozilla Firefox versions up to 132, and Firefox ESR up to 128.4 are affected by CVE-2024-10466.