cve/2024/CVE-2024-2608.md
2025-09-29 16:08:36 +00:00

1.2 KiB

CVE-2024-2608

Description

AppendEncodedAttributeValue(), ExtraSpaceNeededForAttrEncoding() and AppendEncodedCharacters() could have experienced integer overflows, causing underallocation of an output buffer leading to an out of bounds write. This vulnerability affects Firefox < 124, Firefox ESR < 115.9, and Thunderbird < 115.9.

POC

Reference

Github