Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-9394


An attacker could, via a specially crafted multipart response, execute arbitrary JavaScript under the `resource://devtools` origin. This could allow them to access cross-origin JSON content. This access is limited to "same site" documents by the Site Isolation feature on desktop clients, but full cross-origin access is possible on Android versions. This vulnerability affects Firefox < 131, Firefox ESR < 128.3, Firefox ESR < 115.16, Thunderbird < 128.3, and Thunderbird < 131.


Published

2024-10-01T16:15:10.683

Last Modified

2025-03-14T16:15:39.213

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 7.5 (HIGH)

Weaknesses
  • Type: Primary
    NVD-CWE-Other
  • Type: Secondary
    CWE-79

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application mozilla firefox < 131.0 Yes
Application mozilla firefox_esr < 115.16.0 Yes
Application mozilla firefox_esr < 128.3.0 Yes
Application mozilla thunderbird < 128.3 Yes
Application mozilla thunderbird 129.0 Yes
Application mozilla thunderbird 129.0 Yes
Application mozilla thunderbird 129.0 Yes
Application mozilla thunderbird 129.0 Yes
Application mozilla thunderbird 129.0 Yes
Application mozilla thunderbird 129.0 Yes

References