CVE-2024-8384: Use After Free
Last updated 11 September 2024
Other sources
The JavaScript garbage collector could mis-color cross-compartment objects if OOM conditions were detected at the right point between two passes. This could have led to memory corruption.
— Mozilla
This CVE was automatically created from a reference found in an email or other text. If you are reading this, then this CVE entry is probably erroneous, since this text should be replaced by the official CVE description automatically.
— Launchpad
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2024-8384?
CVE-2024-8384 has a significant severity level due to the potential for memory corruption.
How do I fix CVE-2024-8384?
To fix CVE-2024-8384, update to Firefox ESR 128.3 or later, Firefox 131.0 or later, or Thunderbird 128.3 or later.
Which versions are affected by CVE-2024-8384?
CVE-2024-8384 affects Firefox versions up to 130, Firefox ESR versions up to 128.2, and Thunderbird versions up to 115.15.
Can CVE-2024-8384 be exploited remotely?
Yes, CVE-2024-8384 could potentially be exploited remotely if an attacker manipulates how the garbage collector processes cross-compartment objects.
What are the products impacted by CVE-2024-8384?
CVE-2024-8384 impacts Mozilla Firefox, Firefox ESR, and Thunderbird versions specified in the affected software list.