CVE-2024-29944 is a critical vulnerability affecting desktop versions of Firefox (versions prior to 124.0.1 and ESR 115.9.1) that allows an attacker to execute arbitrary JavaScript in the parent process by injecting an event handler into a privileged object. This flaw carries a high CVSS score of 8.4, indicating a severe risk of complete compromise of confidentiality, integrity, and availability, with the attack requiring no user interaction. Notably, this zero-day vulnerability has been actively exploited in the wild, as evidenced by its use in Pwn2Own Berlin and extensive media coverage, despite no public exploit code being readily available.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 115.9.1CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox:*:*:*:*:esr:*:*:* | ||
<= 124.0.1CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:* | ||
10.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.5 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.