Memory safety bugs present in Firefox 127, Firefox ESR 115.12, and Thunderbird 115.12. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 128, Firefox ESR < 115.13, Thunderbird < 115.13, and Thunderbird < 128.
                
            Metrics
Affected Vendors & Products
References
        History
                    Thu, 30 Oct 2025 16:30:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Title | Mozilla: Memory safety bugs fixed in Firefox 128, Firefox ESR 115.13, and Thunderbird 115.13 | Memory safety bugs fixed in Firefox 128, Firefox ESR 115.13, Thunderbird 128, and Thunderbird 115.13 | 
Fri, 04 Apr 2025 15:00:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| First Time appeared | Mozilla Mozilla firefox Mozilla thunderbird | |
| CPEs | cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:* cpe:2.3:a:mozilla:firefox:*:*:*:*:esr:*:*:* cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:* | |
| Vendors & Products | Mozilla Mozilla firefox Mozilla thunderbird | 
Tue, 12 Nov 2024 16:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Metrics | ssvc 
 | 
Fri, 06 Sep 2024 19:30:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Metrics | ssvc 
 | 
 MITRE
                        MITRE
                    Status: PUBLISHED
Assigner: mozilla
Published: 2024-07-09T14:25:57.691Z
Updated: 2025-10-30T16:16:17.696Z
Reserved: 2024-07-09T14:12:56.509Z
Link: CVE-2024-6604
 Vulnrichment
                        Vulnrichment
                    Updated: 2024-08-01T21:41:03.940Z
 NVD
                        NVD
                    Status : Analyzed
Published: 2024-07-09T15:15:12.597
Modified: 2025-04-04T14:42:46.880
Link: CVE-2024-6604
 Redhat
                        Redhat