« Volver al listado

CVE-2024-9396

Estado: AnalizadaAlta (8.8)—

Actualmente se desconoce si este problema se puede explotar, pero puede darse el caso de que la clonación estructurada de determinados objetos pueda provocar daños en la memoria. Esta vulnerabilidad afecta a Firefox < 131, Firefox ESR < 128.3, Thunderbird < 128.3 y Thunderbird < 131.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (2)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2024-9396",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2024-9396",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2024-10-01T19:12:49.374493Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 8.8,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "security@mozilla.org",
      "affectedData": [
        {
          "vendor": "Mozilla",
          "product": "Firefox",
          "versions": [
            {
              "status": "affected",
              "version": "unspecified",
              "lessThan": "131",
              "versionType": "custom"
            }
          ]
        },
        {
          "vendor": "Mozilla",
          "product": "Firefox ESR",
          "versions": [
            {
              "status": "affected",
              "version": "unspecified",
              "lessThan": "128.3",
              "versionType": "custom"
            }
          ]
        },
        {
          "vendor": "Mozilla",
          "product": "Thunderbird",
          "versions": [
            {
              "status": "affected",
              "version": "unspecified",
              "lessThan": "128.3",
              "versionType": "custom"
            }
          ]
        },
        {
          "vendor": "Mozilla",
          "product": "Thunderbird",
          "versions": [
            {
              "status": "affected",
              "version": "unspecified",
              "lessThan": "131",
              "versionType": "custom"
            }
          ]
        }
      ]
    },
    {
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
      "affectedData": [
        {
          "cpes": [
            "cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*"
          ],
          "vendor": "mozilla",
          "product": "firefox",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "lessThan": "131",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "unknown"
        },
        {
          "cpes": [
            "cpe:2.3:a:mozilla:firefox_esr:*:*:*:*:*:*:*:*"
          ],
          "vendor": "mozilla",
          "product": "firefox_esr",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "lessThan": "128.3",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "unknown"
        },
        {
          "cpes": [
            "cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*"
          ],
          "vendor": "mozilla",
          "product": "thunderbird",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "lessThan": "128.3",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "0",
              "lessThan": "131",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "unknown"
        }
      ]
    }
  ],
  "published": "2024-10-01T16:15:10.790",
  "references": [
    {
      "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1912471",
      "tags": [
        "Issue Tracking"
      ],
      "source": "security@mozilla.org"
    },
    {
      "url": "https://www.mozilla.org/security/advisories/mfsa2024-46/",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "security@mozilla.org"
    },
    {
      "url": "https://www.mozilla.org/security/advisories/mfsa2024-47/",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "security@mozilla.org"
    },
    {
      "url": "https://www.mozilla.org/security/advisories/mfsa2024-49/",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "security@mozilla.org"
    },
    {
      "url": "https://www.mozilla.org/security/advisories/mfsa2024-50/",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "security@mozilla.org"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
      "description": [
        {
          "lang": "en",
          "value": "CWE-119"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "It is currently unknown if this issue is exploitable but a condition may arise where the structured clone of certain objects could lead to memory corruption. This vulnerability affects Firefox < 131, Firefox ESR < 128.3, Thunderbird < 128.3, and Thunderbird < 131."
    },
    {
      "lang": "es",
      "value": "Actualmente se desconoce si este problema se puede explotar, pero puede darse el caso de que la clonación estructurada de determinados objetos pueda provocar daños en la memoria. Esta vulnerabilidad afecta a Firefox &lt; 131, Firefox ESR &lt; 128.3, Thunderbird &lt; 128.3 y Thunderbird &lt; 131."
    }
  ],
  "lastModified": "2026-06-17T08:24:29.273",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:mozilla:firefox:*:*:*:*:esr:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "BA7BC46B-62B5-40E4-A4D9-E05B01AA3030",
              "versionEndExcluding": "128.3.0"
            },
            {
              "criteria": "cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "DA47FFCA-3451-462C-8FFB-47143C65E65A",
              "versionEndExcluding": "131.0"
            },
            {
              "criteria": "cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "162E998D-FC05-4428-A848-3073BC879D13",
              "versionEndExcluding": "128.3.0"
            },
            {
              "criteria": "cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9556B29A-F934-4F99-9C7F-6506CA829DB3",
              "versionEndExcluding": "131.0",
              "versionStartIncluding": "129.0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security@mozilla.org"
}