High severity7.5NVD Advisory· Published Sep 6, 2024· Updated Jun 17, 2026
CVE-2024-7652
CVE-2024-7652
Description
An error in the ECMA-262 specification relating to Async Generators could have resulted in a type confusion, potentially leading to memory corruption and an exploitable crash. This vulnerability affects Firefox < 128, Firefox ESR < 115.13, Thunderbird < 115.13, and Thunderbird < 128.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
14cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*+ 4 more
- cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*range: <128.0
- cpe:2.3:a:mozilla:firefox:*:*:*:*:esr:*:*:*range: <115.13.0
- (no CPE)range: <128
- (no CPE)range: unspecified
- (no CPE)range: unspecified
cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*range: <115.13.0
- (no CPE)range: <115.13, <128
- (no CPE)range: unspecified
- osv-coords6 versionspkg:apk/chainguard/firefoxpkg:apk/chainguard/firefox-esrpkg:apk/wolfi/firefoxpkg:rpm/almalinux/firefoxpkg:rpm/almalinux/firefox-x11pkg:rpm/almalinux/thunderbird
< 128-r0+ 5 more
- (no CPE)range: < 128-r0
- (no CPE)range: < 128-r0
- (no CPE)range: < 128-r0
- (no CPE)range: < 128.2.0-1.el9_4.alma.1
- (no CPE)range: < 128.2.0-1.el9_4.alma.1
- (no CPE)range: < 128.2.0-1.el9_4.alma.1
Patches
Vulnerability mechanics
References
6- github.com/tc39/ecma262/security/advisories/GHSA-g38c-wh3c-5h9rnvdThird Party Advisory
- www.mozilla.org/security/advisories/mfsa2024-29/nvdVendor Advisory
- www.mozilla.org/security/advisories/mfsa2024-30/nvdVendor Advisory
- www.mozilla.org/security/advisories/mfsa2024-31/nvdVendor Advisory
- www.mozilla.org/security/advisories/mfsa2024-32/nvdVendor Advisory
- bugzilla.mozilla.org/show_bug.cginvdIssue Tracking
News mentions
0No linked articles in our index yet.