CVE-2024-8385: Critical severity thunderbird vulnerability
A difference in the handling of StructFields and ArrayTypes in WASM could be used to trigger an exploitable type confusion vulnerability.
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2024-8385?
CVE-2024-8385 is classified as a critical vulnerability due to its potential for exploitation through type confusion.
How do I fix CVE-2024-8385?
To fix CVE-2024-8385, update Mozilla Firefox to versions later than 130 or Mozilla Firefox ESR to versions later than 128.2.
What products are affected by CVE-2024-8385?
CVE-2024-8385 affects Mozilla Firefox versions up to 130 and Mozilla Firefox ESR versions up to 128.2, as well as related products like Thunderbird.
What is the nature of the vulnerability described in CVE-2024-8385?
CVE-2024-8385 involves a type confusion vulnerability resulting from improper handling of StructFields and ArrayTypes in WebAssembly.
Could CVE-2024-8385 be exploited remotely?
Yes, CVE-2024-8385 can potentially be exploited remotely, compromising the security of affected systems.