CVE-2024-2606: Mozilla Firefox
Low severity, CVSS 3.7. EPSS: 0.4% chance of exploitation in the next 30 days.
Passing invalid data could have led to invalid wasm values being created, such as arbitrary integers turning into pointer values. This vulnerability affects Firefox < 124.
Affected products
- Mozilla Firefox: before 124.0 (fixed in 124.0)
Published 2024-03-19. Last modified 2026-06-17.