CVE-2024-4775

An iterator stop condition was missing when handling WASM code in the built-in profiler, potentially leading to invalid memory access and undefined behavior. *Note:* This issue only affects the application when the profiler is running. This vulnerability affects Firefox < 126.
Configurations

No configuration.

History

21 Nov 2024, 09:43

Type Values Removed Values Added
References () https://bugzilla.mozilla.org/show_bug.cgi?id=1887332 - () https://bugzilla.mozilla.org/show_bug.cgi?id=1887332 -
References () https://www.mozilla.org/security/advisories/mfsa2024-21/ - () https://www.mozilla.org/security/advisories/mfsa2024-21/ -

03 Jul 2024, 02:08

Type Values Removed Values Added
CWE CWE-431
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.9
Summary
  • (es) Faltaba una condición de detención del iterador al manejar el código WASM en el generador de perfiles integrado, lo que podría provocar un acceso no válido a la memoria y un comportamiento indefinido. *Nota:* Este problema solo afecta a la aplicación cuando el generador de perfiles se está ejecutando. Esta vulnerabilidad afecta a Firefox &lt; 126.

14 May 2024, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-05-14 18:15

Updated : 2024-11-21 09:43


NVD link : CVE-2024-4775

Mitre link : CVE-2024-4775

CVE.ORG link : CVE-2024-4775


JSON object : View

Products Affected

No product.

CWE
CWE-431

Missing Handler