Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Ubuntu USN |
USN-7134-1 | Firefox vulnerabilities |
Mon, 07 Apr 2025 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mozilla
Mozilla firefox Mozilla thunderbird |
|
| CPEs | cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:* cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:* |
|
| Vendors & Products |
Mozilla
Mozilla firefox Mozilla thunderbird |
Wed, 27 Nov 2024 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | firefox: thunderbird: Null Pointer Dereference in PKCS#12 Utility | |
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Tue, 26 Nov 2024 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-476 | |
| Metrics |
cvssV3_1
|
Tue, 26 Nov 2024 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A null pointer dereference may have inadvertently occurred in `pk12util`, and specifically in the `SEC_ASN1DecodeItem_Util` function, when handling malformed or improperly formatted input files. This vulnerability affects Firefox < 133 and Thunderbird < 133. | |
| References |
|
Status: PUBLISHED
Assigner: mozilla
Published:
Updated: 2024-11-26T16:32:23.217Z
Reserved: 2024-11-25T16:29:48.379Z
Link: CVE-2024-11706
Updated: 2024-11-26T16:30:24.551Z
Status : Analyzed
Published: 2024-11-26T14:15:20.080
Modified: 2025-04-07T19:39:00.667
Link: CVE-2024-11706
OpenCVE Enrichment
No data.
Ubuntu USN