AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2024-11704

CRITICAL · CVSS 9.8 EPSS 0.92%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2024-11-26 · Last synced 2026-08-04

CyberRota Analysis

This is a critical severity vulnerability with a CVSS score of 9.8. It affects Firefox.

CVE
CVE-2024-11704
Severity
CRITICAL
CVSS
9.8
EPSS
0.92%
Firefox

Original NVD Description

A double-free issue could have occurred in `sec_pkcs7_decoder_start_decrypt()` when handling an error path. Under specific conditions, the same symmetric key could have been freed twice, potentially leading to memory corruption. This vulnerability affects Firefox < 133, Thunderbird < 133, Firefox ESR < 128.7, and Thunderbird < 128.7.

Related CVEs

Other vulnerabilities affecting the same vendor(s)