CVE-2024-9399: High severity thunderbird vulnerability
A website configured to initiate a specially crafted WebTransport session could crash the Firefox process leading to a denial of service condition.
Other sources
A website configured to initiate a specially crafted WebTransport session could crash the Thunderbird process leading to a denial of service condition.
— Mozilla
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2024-9399?
CVE-2024-9399 has been categorized as a denial of service vulnerability, which can lead to crashing the Firefox process.
How do I fix CVE-2024-9399?
To resolve CVE-2024-9399, upgrade Firefox to version 131 or Thunderbird to version 131 or later.
Which software versions are affected by CVE-2024-9399?
CVE-2024-9399 affects Firefox versions up to 131 and Thunderbird versions up to 131.
What types of attacks does CVE-2024-9399 enable?
CVE-2024-9399 enables attackers to initiate specially crafted WebTransport sessions that could cause crashes.
Is CVE-2024-9399 specific to certain operating systems?
CVE-2024-9399 is primarily a vulnerability in the Firefox and Thunderbird applications regardless of the operating system.