CVE-2024-5688
21Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 8.1epss 1.1%
exploitation probability
1.1%top 37% of all CVEs
observed exploitation
nono source reports it
If a garbage collection was triggered at the right time, a use-after-free could have occurred during object transplant. This vulnerability affects Firefox < 127, Firefox ESR < 115.12, and Thunderbird < 115.12.
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
References
https://bugzilla.mozilla.org/show_bug.cgi?id=1895086https://lists.debian.org/debian-lts-announce/2024/06/msg00000.htmlhttps://lists.debian.org/debian-lts-announce/2024/06/msg00010.htmlhttps://www.mozilla.org/security/advisories/mfsa2024-25/https://www.mozilla.org/security/advisories/mfsa2024-26/https://www.mozilla.org/security/advisories/mfsa2024-28/