CVE-2024-7520: Code Injection
A type confusion bug in WebAssembly could be leveraged by an attacker to potentially achieve code execution.
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2024-7520?
CVE-2024-7520 has been categorized as a high-severity vulnerability due to its potential to allow code execution.
How do I fix CVE-2024-7520?
To fix CVE-2024-7520, update Firefox to version 129 or later, Firefox ESR to version 128.1 or later, or Thunderbird to version 128.1 or later.
What software is affected by CVE-2024-7520?
CVE-2024-7520 affects Firefox versions prior to 129, Firefox ESR versions prior to 128.1, and Thunderbird versions prior to 128.1.
What are the potential impacts of CVE-2024-7520?
CVE-2024-7520 could allow attackers to exploit a type confusion bug in WebAssembly, possibly leading to unauthorized code execution.
Who is the vendor associated with CVE-2024-7520?
The vendor associated with CVE-2024-7520 is Mozilla, responsible for maintaining Firefox and Thunderbird.