Summary
Mozilla has released security updates to fix a number of vulnerabilities, including five with ‘high’ severity, in Firefox and Firefox ESR products.
Risk
Estimated impact of the vulnerability on the target community: HIGH/ORANGE (65.12/100)1.
Type
- Arbitrary Code Execution
- Denial of Service
- Security Restrictions Bypass
Affected products and versions
- Firefox, versions prior to 127
- Firefox ESR, versions prior to 115.12
Mitigation actions
In line with vendor statements, it is recommended that affected products be updated according to the security bulletins in the References section.
Unique Vulnerability Identifiers
Below are only the CVEs relating to vulnerabilities with ‘high’ severity:
References
https://www.mozilla.org/en-US/security/advisories/mfsa2024-25
https://www.mozilla.org/en-US/security/advisories/mfsa2024-26
1This estimate is made taking into account several parameters, including: CVSS, availability of patches/workarounds and PoCs, prevalence of affected software/devices in the relevant community.