CVE-2024-9936: Race Condition
Published Oct 14, 2024
·Updated
Last updated 22 October 2024
Other sources
When manipulating the selection node cache, an attacker may have been able to cause unexpected behavior, potentially leading to an exploitable crash.
— Mozilla
Affected Software
3 affected componentsFixes available
debian/firefox
132.0-1
Mozilla Firefox<131.0.3
131.0.3
Mozilla Firefox<131.0.3
Event History
Oct 14, 2024
CVE Published
via Mozilla·12:00 AM
CVE Published
via MITRE·01:41 PM
Data Sourced
via MITRE·01:41 PM
DescriptionWeakness
Data Sourced
via NVD·02:15 PM
Description
Data Sourced
via NVD·02:15 PM
SeverityWeakness
Oct 26, 2024
Data Sourced
via Ubuntu·07:42 AM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-9936?
CVE-2024-9936 has been classified as a moderate severity vulnerability.
2
How do I fix CVE-2024-9936?
To fix CVE-2024-9936, update your affected software to at least Firefox version 132.0-1.
3
What software is affected by CVE-2024-9936?
CVE-2024-9936 affects Mozilla Firefox versions prior to 132.0 and the Debian package of Firefox versions prior to 132.0-1.
4
What can an attacker do with CVE-2024-9936?
An attacker exploiting CVE-2024-9936 may manipulate the selection node cache, potentially leading to crashes.
5
Is CVE-2024-9936 exploitable remotely?
Yes, CVE-2024-9936 may be exploitable remotely through malicious web pages.