CVE-2024-8381
CRITICALFirefox < 130 - Type Confusion
Title source: llmDescription
A potentially exploitable type confusion could be triggered when looking up a property name on an object being used as the `with` environment. This vulnerability affects Firefox < 130, Firefox ESR < 128.2, Firefox ESR < 115.15, Thunderbird < 128.2, and Thunderbird < 115.15.
Exploits (1)
References (8)
Scores
CVSS v3
9.8
EPSS
0.1162
EPSS Percentile
93.7%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-843
Status
published
Products (2)
mozilla/firefox
< 130.0
mozilla/firefox_esr
< 115.15
Published
Sep 03, 2024
Tracked Since
Feb 18, 2026