CVE-2024-5696: High severity thunderbird vulnerability
By manipulating the text in an <input> tag, an attacker could have caused corrupt memory leading to a potentially exploitable crash. This vulnerability affects Firefox < 127, Firefox ESR < 115.12, and Thunderbird < 115.12.
Other sources
By manipulating the text in an <input> tag, an attacker could have caused corrupt memory leading to a potentially exploitable crash.
External Reference: https://www.mozilla.org/en-US/security/advisories/mfsa2024-26/#CVE-2024-5696
— Red Hat
By manipulating the text in an <input> tag, an attacker could have caused corrupt memory leading to a potentially exploitable crash.
— Mozilla
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2024-5696?
CVE-2024-5696 has a severity rating that indicates a high potential for exploitation due to memory corruption issues.
How do I fix CVE-2024-5696?
To fix CVE-2024-5696, update your Mozilla Firefox ESR, Thunderbird, or related packages to the recommended versions listed in the advisory.
Which versions are affected by CVE-2024-5696?
CVE-2024-5696 affects Mozilla Firefox ESR versions up to 115.12, Thunderbird versions up to 115.12, and various package versions specified in the advisory.
What products are impacted by CVE-2024-5696?
CVE-2024-5696 impacts Mozilla Firefox, Mozilla Thunderbird, and their respective packages on several platforms.
What kind of attack vector is associated with CVE-2024-5696?
CVE-2024-5696 can be exploited through malicious manipulation of text within an <input> tag, potentially causing application crashes.