RHSA-2024:7621HighCVSS 7.6

Red Hat Security Advisory: firefox security update

Published
October 3, 2024
Last Modified
June 25, 2026

🔗 CVE IDs covered (12)

📋 Description

CVE-2024-8900 — firefox: Clipboard write permission bypass CVE-2024-9392 — firefox: thunderbird: Compromised content process can bypass site isolation CVE-2024-9393 — firefox: thunderbird: Cross-origin access to PDF contents through multipart responses CVE-2024-9394 — firefox: thunderbird: Cross-origin access to JSON contents through multipart responses CVE-2024-9396 — firefox: thunderbird: Potential memory corruption may occur when cloning certain objects CVE-2024-9397 — firefox: thunderbird: Potential directory upload bypass via clickjacking CVE-2024-9398 — firefox: thunderbird: External protocol handlers could be enumerated via popups CVE-2024-9399 — firefox: thunderbird: Specially crafted WebTransport requests could lead to denial of service CVE-2024-9400 — firefox: thunderbird: Potential memory corruption during JIT compilation CVE-2024-9401 — firefox: thunderbird: Memory safety bugs fixed in Firefox 131, Firefox ESR 115.16, Firefox ESR 128.3, Thunderbird 131, and Thunderbird 128.3 CVE-2024-9402 — firefox: thunderbird: Memory safety bugs fixed in Firefox 131, Firefox ESR 128.3, Thunderbird 131, and Thunderbird 128.3 CVE-2024-9403 — firefox: thunderbird: Memory safety bugs fixed in Firefox 131 and Thunderbird 131

🔗 References (14)