CVE-2024-8381: Critical severity thunderbird vulnerability
A potentially exploitable type confusion could be triggered when looking up a property name on an object being used as the with environment. This vulnerability affects Firefox < 130, Firefox ESR < 128.2, and Firefox ESR < 115.15.
Other sources
A potentially exploitable type confusion could be triggered when looking up a property name on an object being used as the with environment. This vulnerability affects Firefox < 130, Firefox ESR < 128.2, Firefox ESR < 115.15, Thunderbird < 128.2, and Thunderbird < 115.15.
— MITRE
A potentially exploitable type confusion could be triggered when looking up a property name on an object being used as the with environment.
— Mozilla
This CVE was automatically created from a reference found in an email or other text. If you are reading this, then this CVE entry is probably erroneous, since this text should be replaced by the official CVE description automatically.
— Launchpad
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2024-8381?
CVE-2024-8381 is considered a potentially exploitable vulnerability due to type confusion in affected versions of Firefox.
How do I fix CVE-2024-8381?
To fix CVE-2024-8381, update Firefox to version 130 or later, or update Firefox ESR to version 128.2 or later.
What versions are affected by CVE-2024-8381?
CVE-2024-8381 affects Firefox versions prior to 130, Firefox ESR versions prior to 128.2, and Firefox ESR versions prior to 115.15.
Can CVE-2024-8381 be exploited remotely?
Yes, CVE-2024-8381 may allow remote code execution through crafted web content.
Which products are impacted by CVE-2024-8381?
CVE-2024-8381 impacts Mozilla Firefox, Mozilla Firefox ESR, and Mozilla Thunderbird versions below the specified remedies.