Unrated severityNVD Advisory· Published May 14, 2024· Updated Mar 28, 2025
CVE-2024-4767
CVE-2024-4767
Description
If the browser.privatebrowsing.autostart preference is enabled, IndexedDB files were not properly deleted when the window was closed. This preference is disabled by default in Firefox. This vulnerability affects Firefox < 126, Firefox ESR < 115.11, and Thunderbird < 115.11.
Affected products
34- osv-coords31 versionspkg:apk/chainguard/firefox-esrpkg:rpm/almalinux/firefoxpkg:rpm/almalinux/firefox-x11pkg:rpm/almalinux/thunderbirdpkg:rpm/opensuse/firefox-esr&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/MozillaFirefox&distro=openSUSE%20Leap%2015.5pkg:rpm/opensuse/MozillaFirefox&distro=openSUSE%20Leap%2015.6pkg:rpm/opensuse/MozillaFirefox&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/MozillaThunderbird&distro=openSUSE%20Leap%2015.5pkg:rpm/opensuse/MozillaThunderbird&distro=openSUSE%20Leap%2015.6pkg:rpm/opensuse/MozillaThunderbird&distro=openSUSE%20Tumbleweedpkg:rpm/suse/MozillaFirefox&distro=SUSE%20Enterprise%20Storage%207.1pkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP2-LTSSpkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP3-LTSSpkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP4-ESPOSpkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP4-LTSSpkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Desktop%20Applications%2015%20SP5pkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Desktop%20Applications%2015%20SP6pkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP5pkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP2-LTSSpkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP3-LTSSpkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP4-LTSSpkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP5pkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP2pkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP3pkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP4pkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP5pkg:rpm/suse/MozillaThunderbird&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Package%20Hub%2015%20SP5pkg:rpm/suse/MozillaThunderbird&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Package%20Hub%2015%20SP6pkg:rpm/suse/MozillaThunderbird&distro=SUSE%20Linux%20Enterprise%20Workstation%20Extension%2015%20SP5pkg:rpm/suse/MozillaThunderbird&distro=SUSE%20Linux%20Enterprise%20Workstation%20Extension%2015%20SP6
< 115.11.0-r0+ 30 more
- (no CPE)range: < 115.11.0-r0
- (no CPE)range: < 115.11.0-1.el9_4.alma.1
- (no CPE)range: < 115.11.0-1.el9_4.alma.1
- (no CPE)range: < 115.11.0-1.el9_4.alma.1
- (no CPE)range: < 128.5.1-1.1
- (no CPE)range: < 115.11.0-150200.152.137.2
- (no CPE)range: < 115.11.0-150200.152.137.2
- (no CPE)range: < 126.0-1.1
- (no CPE)range: < 115.11.0-150200.8.160.1
- (no CPE)range: < 115.11.0-150200.8.160.1
- (no CPE)range: < 115.11.0-1.1
- (no CPE)range: < 115.11.0-150200.152.137.2
- (no CPE)range: < 115.11.0-150200.152.137.2
- (no CPE)range: < 115.11.0-150200.152.137.2
- (no CPE)range: < 115.11.0-150200.152.137.2
- (no CPE)range: < 115.11.0-150200.152.137.2
- (no CPE)range: < 115.11.0-150200.152.137.2
- (no CPE)range: < 115.11.0-150200.152.137.2
- (no CPE)range: < 115.11.0-112.212.1
- (no CPE)range: < 115.11.0-150200.152.137.2
- (no CPE)range: < 115.11.0-150200.152.137.2
- (no CPE)range: < 115.11.0-150200.152.137.2
- (no CPE)range: < 115.11.0-112.212.1
- (no CPE)range: < 115.11.0-150200.152.137.2
- (no CPE)range: < 115.11.0-150200.152.137.2
- (no CPE)range: < 115.11.0-150200.152.137.2
- (no CPE)range: < 115.11.0-112.212.1
- (no CPE)range: < 115.11.0-150200.8.160.1
- (no CPE)range: < 115.11.0-150200.8.160.1
- (no CPE)range: < 115.11.0-150200.8.160.1
- (no CPE)range: < 115.11.0-150200.8.160.1
- Range: unspecified
- Range: unspecified
- Range: unspecified
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
6- bugzilla.mozilla.org/show_bug.cgimitre
- lists.debian.org/debian-lts-announce/2024/05/msg00010.htmlmitre
- lists.debian.org/debian-lts-announce/2024/05/msg00012.htmlmitre
- www.mozilla.org/security/advisories/mfsa2024-21/mitre
- www.mozilla.org/security/advisories/mfsa2024-22/mitre
- www.mozilla.org/security/advisories/mfsa2024-23/mitre
News mentions
0No linked articles in our index yet.