On 32-bit versions there were integer-overflows that led to an out-of-bounds-read that potentially could be triggered by a malformed OpenType font. This vulnerability affects Firefox < 125, Firefox ESR < 115.10, and Thunderbird < 115.10.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mozilla
Published: 2024-04-16T15:14:07.543Z
Updated: 2024-08-01T20:26:56.940Z
Reserved: 2024-04-15T20:26:52.691Z
Link: CVE-2024-3859
Vulnrichment
Updated: 2024-08-01T20:26:56.940Z
NVD
Status : Awaiting Analysis
Published: 2024-04-16T16:15:08.663
Modified: 2024-07-03T02:06:47.757
Link: CVE-2024-3859
Redhat