← Back to browse · API

CVE-2024-8381

Severity
CRITICAL
CVSS
9.8
EPSS
0.04395
Risk score
40.74
CISA KEV
No
PoC
No
Published
2024-09-03
Modified
2025-11-04
First seen
2026-08-07
Aliases
EUVD-2024-49137, GHSA-X565-97FV-JFR5
Products
Mozilla:Firefox ESR unspecified <115.15, Mozilla:Firefox ESR unspecified <128.2, Mozilla:Firefox unspecified <130, Mozilla:Thunderbird unspecified <115.15, Mozilla:Thunderbird unspecified <128.2
Sources
euvd EUVD-2024-49137

Description

A potentially exploitable type confusion could be triggered when looking up a property name on an object being used as the `with` environment. This vulnerability affects Firefox < 130, Firefox ESR < 128.2, Firefox ESR < 115.15, Thunderbird < 128.2, and Thunderbird < 115.15.

References