CVE-2024-29943: Integer Overflow
Published Mar 22, 2024
·Updated
An attacker was able to perform an out-of-bounds read or write on a JavaScript object by fooling range-based bounds check elimination. This vulnerability affects Firefox < 124.0.1.
Affected Software
4 affected componentsFixes available
ubuntu/firefox<124.0.1+
124.0.1+
debian/firefox
126.0-1
Mozilla Firefox<124.0.1
124.0.1
Mozilla Firefox<124.0.1
Event History
Mar 22, 2024
CVE Published
via Ubuntu·12:00 AM
CVE Published
via MITRE·12:55 PM
Data Sourced
via MITRE·12:55 PM
DescriptionWeakness
Data Sourced
via NVD·01:15 PM
Description
News Published
via BleepingComputer·05:45 PM
News Published
via BleepingComputer·05:47 PM
Mar 25, 2024
News Published
via The Register·03:00 PM
News Published
via The Register·03:04 PM
Mar 29, 2024
Data Sourced
via Launchpad·05:30 AM
Description
Oct 9, 2024
News Published
via BleepingComputer·05:34 PM
May 19, 2025
News Published
via BleepingComputer·02:03 PM
May 23, 2025
Known Exploited
02:05 PM
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
1
What is the severity of CVE-2024-29943?
CVE-2024-29943 has a high severity rating due to potential exploitation that allows out-of-bounds read or write operations.
2
How do I fix CVE-2024-29943?
To fix CVE-2024-29943, update your Firefox browser to version 124.0.1 or later.
3
Which versions of Firefox are affected by CVE-2024-29943?
CVE-2024-29943 affects all Firefox versions prior to 124.0.1.
4
Can CVE-2024-29943 be exploited remotely?
Yes, CVE-2024-29943 can be exploited remotely if the user visits a malicious website.
5
What types of attacks can CVE-2024-29943 facilitate?
CVE-2024-29943 can facilitate memory corruption attacks, which can lead to arbitrary code execution.