When Responsive Design Mode was enabled, it used references to objects that were previously freed. We presume that with enough effort this could have been exploited to run arbitrary code. This vulnerability affects Firefox ESR < 78.10, Thunderbird < 78.10, and Firefox < 88.
oryginał ENCVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HMozilla Firefox
APPMozilla< 88.0Mozilla Firefox Esr
APPMozilla< 78.10Mozilla Thunderbird
APPMozilla< 78.10
🔵
ZWERYFIKUJ U PRODUCENTA
Brak jednoznacznych danych o patchu. Sprawdź referencje od producenta.
CWE
Referencje
Powiązane podatności
CVE-2024-9680CRITICAL9.8⚠ KEVPL ✓ten sam produkt
Use-after-free w Animation timelines Firefox/Thunderbird — RCE
CVE-2022-26486CRITICAL9.6⚠ KEVPL ✓ten sam produkt
Use-after-free w WebGPU IPC framework Mozilla — sandbox escape
CVE-2019-11708CRITICAL10.0⚠ KEVPL ✓ten sam produkt
Mozilla Firefox/Thunderbird: przełamanie sandbox przez IPC Prompt:Open
CVE-2010-3765CRITICAL9.8⚠ KEVPL ✓ten sam produkt
RCE w Mozilla Firefox przez błąd nsCSSFrameConstructor::ContentAppended
CVE-2026-84119CRITICAL9.6ten sam produkt
Sandbox escape due to use-after-free in the DOM: Navigation component. This vulnerability was fixed in Firefox...