CVE-2024-29944: Integer Overflow
An attacker was able to inject an event handler into a privileged object that would allow arbitrary JavaScript execution in the parent process. Note: This vulnerability affects Desktop Firefox only, it does not affect mobile versions of Firefox. This vulnerability affects Firefox < 124.0.1 and Firefox ESR < 115.9.1.
Other sources
An attacker was able to inject an event handler into a privileged object that would allow arbitrary JavaScript execution in the parent process.
External Reference: https://www.mozilla.org/en-US/security/advisories/mfsa2024-16/#CVE-2024-29944
— Red Hat
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2024-29944?
CVE-2024-29944 is considered a critical vulnerability due to its potential for arbitrary JavaScript execution.
Who is affected by CVE-2024-29944?
CVE-2024-29944 affects users of Desktop Firefox versions prior to 124.0.1 and Firefox ESR versions before 115.9.1.
How do I fix CVE-2024-29944?
To fix CVE-2024-29944, update Firefox to version 124.0.1 or later, or Firefox ESR to version 115.9.1 or later.
What types of systems are vulnerable to CVE-2024-29944?
CVE-2024-29944 affects desktop environments running Mozilla Firefox on Windows, macOS, and Linux.
Can mobile versions of Firefox be impacted by CVE-2024-29944?
No, CVE-2024-29944 does not affect mobile versions of Firefox.