CVE-2024-3864: Buffer Overflow
Last updated 24 July 2024
Other sources
Memory safety bug present in Firefox 124, Firefox ESR 115.9, and Thunderbird 115.9. This bug showed evidence of memory corruption and we presume that with enough effort this could have been exploited to run arbitrary code.
— Mozilla
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2024-3864?
CVE-2024-3864 is categorized as a memory safety vulnerability which is suspected to allow the execution of arbitrary code.
How do I fix CVE-2024-3864?
To fix CVE-2024-3864, update to Firefox version 115.10, Thunderbird version 115.10, or the corresponding patched version in your distribution.
Which versions of Firefox and Thunderbird are affected by CVE-2024-3864?
CVE-2024-3864 affects Firefox 124, Firefox ESR 115.9, and Thunderbird 115.9.
Is CVE-2024-3864 present in older versions of Firefox or Thunderbird?
Yes, CVE-2024-3864 is present in all versions prior to Firefox 115.10 and Thunderbird 115.10.
Will updating to the latest version resolve CVE-2024-3864?
Yes, updating to the specified versions will remediate the vulnerability associated with CVE-2024-3864.