CVE-2024-11699: Code Injection
Last updated 3 December 2024
Other sources
Memory safety bugs present in Firefox 132, Firefox ESR 128.4, and Thunderbird 128.4. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code.
— Mozilla
Memory safety bugs present in Firefox 132, Thunderbird 132, Firefox ESR 128.4, and Thunderbird 128.4. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code.
— Mozilla
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2024-11699?
CVE-2024-11699 is a memory safety bug that could potentially allow attackers to run arbitrary code.
How do I fix CVE-2024-11699?
To fix CVE-2024-11699, upgrade to Mozilla Thunderbird version 133 or 128.5, or Mozilla Firefox version 133 or Firefox ESR version 128.5.
Which software is affected by CVE-2024-11699?
CVE-2024-11699 affects Firefox 132, Firefox ESR 128.4, and Thunderbird 128.4.
Can CVE-2024-11699 be exploited?
There is evidence that the memory safety bugs in CVE-2024-11699 could potentially be exploited with significant effort.
What versions are safe from CVE-2024-11699?
Safe versions include Mozilla Thunderbird 133 and 128.5, Mozilla Firefox 133, and Firefox ESR 128.5.