CVE-2024-10467: Critical severity thunderbird vulnerability
Last updated 6 November 2024
Other sources
Memory safety bugs present in Firefox 131, Firefox ESR 128.3, and Thunderbird 128.3. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code.
— Mozilla
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2024-10467?
CVE-2024-10467 has a high severity rating due to potential memory corruption allowing arbitrary code execution.
How do I fix CVE-2024-10467?
To fix CVE-2024-10467, update Firefox and Thunderbird to version 132.0 or later, or Firefox ESR and Thunderbird to version 128.4.
What versions of Firefox are affected by CVE-2024-10467?
Affected versions of Firefox include 131 and versions below 132.
What versions of Thunderbird are impacted by CVE-2024-10467?
Thunderbird versions 128.3 and below 132 are impacted by CVE-2024-10467.
Can CVE-2024-10467 be exploited remotely?
Yes, CVE-2024-10467 may be exploited remotely given its memory safety vulnerabilities.