Manfred Paul discovered that Firefox did not properly perform bounds checking during range analysis, leading to an out-of-bounds write vulnerability. A attacker could use this to cause a denial of service, or execute arbitrary code. (CVE-2024-29943)
Manfred Paul discovered that Firefox incorrectly handled MessageManager listeners under certain circumstances. An attacker who was able to inject an event handler into a privileged object may have been able to execute arbitrary code. (CVE-2024-29944)
{
    "binaries": [
        {
            "binary_version": "124.0.1+build1-0ubuntu0.20.04.1",
            "binary_name": "firefox"
        },
        {
            "binary_version": "124.0.1+build1-0ubuntu0.20.04.1",
            "binary_name": "firefox-dev"
        },
        {
            "binary_version": "124.0.1+build1-0ubuntu0.20.04.1",
            "binary_name": "firefox-geckodriver"
        },
        {
            "binary_version": "124.0.1+build1-0ubuntu0.20.04.1",
            "binary_name": "firefox-mozsymbols"
        }
    ],
    "availability": "No subscription required"
}
          {
    "ecosystem": "Ubuntu:20.04:LTS",
    "cves": [
        {
            "severity": [
                {
                    "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "type": "CVSS_V3"
                },
                {
                    "score": "medium",
                    "type": "Ubuntu"
                }
            ],
            "id": "CVE-2024-29943"
        },
        {
            "severity": [
                {
                    "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "type": "CVSS_V3"
                },
                {
                    "score": "medium",
                    "type": "Ubuntu"
                }
            ],
            "id": "CVE-2024-29944"
        }
    ]
}