CVE-2024-10464
firefox: thunderbird: History interface could have been used to cause a Denial of Service condition in the browser
Severity Score
Exploit Likelihood
Affected Versions
31Public Exploits
0Exploited in Wild
-Decision
Descriptions
Repeated writes to history interface attributes could have been used to cause a Denial of Service condition in the browser. This was addressed by introducing rate-limiting to this API. This vulnerability affects Firefox < 132, Firefox ESR < 128.4, Thunderbird < 128.4, and Thunderbird < 132.
The Mozilla Foundation's Security Advisory: Repeated writes to history interface attributes could be used to cause a Denial of Service condition in the browser. This issue was addressed by introducing rate-limiting to this API.
Multiple security issues were discovered in Firefox. If a user were tricked into opening a specially crafted website, an attacker could potentially exploit these to cause a denial of service, obtain sensitive information across domains, or execute arbitrary code.
CVSS Scores
SSVC
- Decision:Attend
Timeline
- 2024-10-28 CVE Reserved
- 2024-10-29 CVE Published
- 2024-10-29 CVE Updated
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-125: Out-of-bounds Read
- CWE-799: Improper Control of Interaction Frequency
CAPEC
References (7)
URL | Date | SRC |
---|
URL | Date | SRC |
---|