The SentinelOne Annual Threat Report - A Defenders Guide from the FrontlinesThe SentinelOne Annual Threat ReportGet the Report
Experiencing a Breach?Blog
Get StartedContact Us
SentinelOne
  • Platform
    Platform Overview
    • Singularity Platform
      Welcome to Integrated Enterprise Security
    • AI for Security
      Leading the Way in AI-Powered Security Solutions
    • Securing AI
      Accelerate AI Adoption with Secure AI Tools, Apps, and Agents.
    • How It Works
      The Singularity XDR Difference
    • Singularity Marketplace
      One-Click Integrations to Unlock the Power of XDR
    • Pricing & Packaging
      Comparisons and Guidance at a Glance
    Data & AI
    • Purple AI
      Accelerate SecOps with Generative AI
    • Singularity Hyperautomation
      Easily Automate Security Processes
    • AI-SIEM
      The AI SIEM for the Autonomous SOC
    • AI Data Pipelines
      Security Data Pipeline for AI SIEM and Data Optimization
    • Singularity Data Lake
      AI-Powered, Unified Data Lake
    • Singularity Data Lake for Log Analytics
      Seamlessly Ingest Data from On-Prem, Cloud or Hybrid Environments
    Endpoint Security
    • Singularity Endpoint
      Autonomous Prevention, Detection, and Response
    • Singularity XDR
      Native & Open Protection, Detection, and Response
    • Singularity RemoteOps Forensics
      Orchestrate Forensics at Scale
    • Singularity Threat Intelligence
      Comprehensive Adversary Intelligence
    • Singularity Vulnerability Management
      Application & OS Vulnerability Management
    • Singularity Identity
      Identity Threat Detection and Response
    Cloud Security
    • Singularity Cloud Security
      Block Attacks with an AI-Powered CNAPP
    • Singularity Cloud Native Security
      Secure Cloud and Development Resources
    • Singularity Cloud Workload Security
      Real-Time Cloud Workload Protection Platform
    • Singularity Cloud Data Security
      AI-Powered Threat Detection for Cloud Storage
    • Singularity Cloud Security Posture Management
      Detect and Remediate Cloud Misconfigurations
    Securing AI
    • Prompt Security
      Secure AI Tools Across Your Enterprise
  • Why SentinelOne?
    Why SentinelOne?
    • Why SentinelOne?
      Cybersecurity Built for What’s Next
    • Our Customers
      Trusted by the World’s Leading Enterprises
    • Industry Recognition
      Tested and Proven by the Experts
    • About Us
      The Industry Leader in Autonomous Cybersecurity
    Compare SentinelOne
    • Arctic Wolf
    • Broadcom
    • CrowdStrike
    • Cybereason
    • Microsoft
    • Palo Alto Networks
    • Sophos
    • Splunk
    • Trellix
    • Trend Micro
    • Wiz
    Verticals
    • Energy
    • Federal Government
    • Finance
    • Healthcare
    • Higher Education
    • K-12 Education
    • Manufacturing
    • Retail
    • State and Local Government
  • Services
    Managed Services
    • Managed Services Overview
      Wayfinder Threat Detection & Response
    • Threat Hunting
      World-Class Expertise and Threat Intelligence
    • Managed Detection & Response
      24/7/365 Expert MDR Across Your Entire Environment
    • Incident Readiness & Response
      DFIR, Breach Readiness, & Compromise Assessments
    Support, Deployment, & Health
    • Technical Account Management
      Customer Success with Personalized Service
    • SentinelOne GO
      Guided Onboarding & Deployment Advisory
    • SentinelOne University
      Live and On-Demand Training
    • Services Overview
      Comprehensive Solutions for Seamless Security Operations
    • SentinelOne Community
      Community Login
  • Partners
    Our Network
    • MSSP Partners
      Succeed Faster with SentinelOne
    • Singularity Marketplace
      Extend the Power of S1 Technology
    • Cyber Risk Partners
      Enlist Pro Response and Advisory Teams
    • Technology Alliances
      Integrated, Enterprise-Scale Solutions
    • SentinelOne for AWS
      Hosted in AWS Regions Around the World
    • Channel Partners
      Deliver the Right Solutions, Together
    • SentinelOne for Google Cloud
      Unified, Autonomous Security Giving Defenders the Advantage at Global Scale
    • Partner Locator
      Your Go-to Source for Our Top Partners in Your Region
    Partner Portal→
  • Resources
    Resource Center
    • Case Studies
    • Data Sheets
    • eBooks
    • Reports
    • Videos
    • Webinars
    • Whitepapers
    • Events
    View All Resources→
    Blog
    • Feature Spotlight
    • For CISO/CIO
    • From the Front Lines
    • Identity
    • Cloud
    • macOS
    • SentinelOne Blog
    Blog→
    Tech Resources
    • SentinelLABS
    • Ransomware Anthology
    • Cybersecurity 101
  • About
    About SentinelOne
    • About SentinelOne
      The Industry Leader in Cybersecurity
    • Investor Relations
      Financial Information & Events
    • SentinelLABS
      Threat Research for the Modern Threat Hunter
    • Careers
      The Latest Job Opportunities
    • Press & News
      Company Announcements
    • Cybersecurity Blog
      The Latest Cybersecurity Threats, News, & More
    • FAQ
      Get Answers to Our Most Frequently Asked Questions
    • DataSet
      The Live Data Platform
    • S Foundation
      Securing a Safer Future for All
    • S Ventures
      Investing in the Next Generation of Security, Data and AI
  • Pricing
Get StartedContact Us
CVE Vulnerability Database
Vulnerability Database/CVE-2024-0746

CVE-2024-0746: Mozilla Firefox DOS Vulnerability

CVE-2024-0746 is a denial of service vulnerability in Mozilla Firefox that causes browser crashes when Linux users open print preview. This article covers technical details, affected versions, impact, and mitigation.

Published: April 15, 2026

CVE-2024-0746 Overview

A use-after-free vulnerability exists in Mozilla Firefox, Firefox ESR, and Thunderbird that can be triggered when a Linux user opens the print preview dialog. This vulnerability causes the browser to crash, resulting in a denial of service condition. The flaw affects the print preview functionality specifically on Linux-based systems, where improper memory handling during the dialog rendering process leads to application instability.

Critical Impact

This vulnerability allows remote attackers to cause a denial of service by crafting malicious content that triggers a browser crash when a user attempts to print preview, disrupting user productivity and potentially causing data loss from unsaved work.

Affected Products

  • Mozilla Firefox versions prior to 122
  • Mozilla Firefox ESR versions prior to 115.7
  • Mozilla Thunderbird versions prior to 115.7
  • Debian Linux 10.0

Discovery Timeline

  • 2024-01-23 - CVE CVE-2024-0746 published to NVD
  • 2025-06-20 - Last updated in NVD database

Technical Details for CVE-2024-0746

Vulnerability Analysis

This vulnerability is classified as a Use-After-Free (CWE-416) condition affecting Mozilla's browser products on Linux systems. The flaw occurs within the print preview dialog functionality, where memory that has been freed is subsequently accessed, leading to undefined behavior and an application crash.

The vulnerability requires user interaction to exploit, as the victim must open the print preview dialog for the crash to occur. While no confidentiality or integrity impact has been identified, the availability impact is significant as it causes immediate application termination. An attacker could leverage this vulnerability to disrupt browser functionality, potentially as part of a larger attack chain or simply to cause denial of service.

Root Cause

The root cause of this vulnerability is improper memory management within the print preview dialog implementation on Linux platforms. When the print preview dialog is opened, certain memory resources are freed prematurely while still being referenced by other components of the dialog rendering process. This creates a dangling pointer that, when dereferenced, causes the browser to crash.

The issue appears to be specific to the Linux implementation of the print preview functionality, suggesting platform-specific code paths that handle printing operations differently than on Windows or macOS. The bug report tracked as Mozilla Bug Report #1660223 contains additional technical details about the specific memory handling issue.

Attack Vector

The attack vector is network-based, requiring user interaction to trigger the vulnerability. An attacker could exploit this vulnerability by:

  1. Hosting malicious content on a website designed to encourage users to print the page
  2. Sending crafted HTML emails through Thunderbird that prompt the user to preview printing
  3. Embedding content in web pages that triggers automatic print dialogs (though browsers typically block unsolicited print dialogs)

When a user on a Linux system opens the print preview dialog while viewing the attacker-controlled content, the browser crashes. While this does not directly lead to code execution, the consistent crash behavior could be used to:

  • Disrupt user workflow and cause frustration
  • Potentially mask other malicious activities by repeatedly crashing the browser
  • Create conditions for further exploitation if combined with other vulnerabilities

The vulnerability manifests in the print preview dialog handling code on Linux systems. When the dialog is opened, improper memory lifecycle management causes previously freed memory to be accessed, resulting in a crash. See the Mozilla Security Advisory MFSA-2024-01 for official technical details.

Detection Methods for CVE-2024-0746

Indicators of Compromise

  • Unexpected Firefox, Firefox ESR, or Thunderbird crashes on Linux systems, particularly when users attempt to print or access print preview
  • Crash reports in browser telemetry or system logs indicating memory access violations in print-related code paths
  • Multiple instances of browser restarts in quick succession associated with print preview actions
  • User reports of browsers closing unexpectedly when attempting to print web pages or emails

Detection Strategies

  • Monitor application crash logs for Firefox and Thunderbird processes with signatures matching use-after-free conditions in print dialog components
  • Implement endpoint detection rules that flag repeated browser crashes occurring within print preview operations
  • Deploy network monitoring to detect access to known malicious pages designed to exploit this vulnerability
  • Utilize SentinelOne's behavioral analysis to identify patterns of repeated application crashes that may indicate exploitation attempts

Monitoring Recommendations

  • Enable Mozilla crash reporting to collect detailed crash data for security analysis
  • Configure endpoint monitoring solutions to alert on abnormal application termination rates for affected Mozilla products
  • Review system logs on Linux endpoints for segmentation fault signals associated with Firefox or Thunderbird processes
  • Implement centralized logging for browser crash events to identify potential targeted exploitation campaigns

How to Mitigate CVE-2024-0746

Immediate Actions Required

  • Update Mozilla Firefox to version 122 or later on all Linux systems
  • Update Mozilla Firefox ESR to version 115.7 or later across enterprise deployments
  • Update Thunderbird to version 115.7 or later to protect email clients
  • Apply Debian security updates as referenced in the Debian LTS announcements
  • Verify updates have been successfully applied through version checks

Patch Information

Mozilla has released security patches addressing this vulnerability in the following versions:

  • Firefox 122: Includes the fix for this use-after-free vulnerability
  • Firefox ESR 115.7: Extended Support Release with the security fix
  • Thunderbird 115.7: Email client patched against this vulnerability

Official security advisories are available from Mozilla:

  • Mozilla Security Advisory MFSA-2024-01 (Firefox)
  • Mozilla Security Advisory MFSA-2024-02 (Firefox ESR)
  • Mozilla Security Advisory MFSA-2024-04 (Thunderbird)

Debian users should refer to the Debian LTS Announce - January 22, 2024 for distribution-specific patching instructions.

Workarounds

  • Advise Linux users to avoid using print preview functionality until patches are applied
  • Consider temporarily using alternative browsers for printing tasks on unpatched Linux systems
  • Deploy browser policies that restrict printing functionality if immediate patching is not possible
  • Implement network-level controls to block access to known malicious domains targeting this vulnerability
bash
# Update Firefox on Debian/Ubuntu systems
sudo apt update && sudo apt upgrade firefox

# Update Thunderbird on Debian/Ubuntu systems
sudo apt update && sudo apt upgrade thunderbird

# Verify Firefox version (should be 122 or later)
firefox --version

# Verify Thunderbird version (should be 115.7 or later)
thunderbird --version

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

  • Vulnerability Details
  • TypeDOS

  • Vendor/TechMozilla Firefox

  • SeverityMEDIUM

  • CVSS Score6.5

  • EPSS Probability0.45%

  • Known ExploitedNo
  • CVSS Vector
  • CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
  • Impact Assessment
  • ConfidentialityLow
  • IntegrityNone
  • AvailabilityHigh
  • CWE References
  • NVD-CWE-noinfo

  • CWE-416
  • Technical References
  • Mozilla Bug Report #1660223

  • Debian LTS Announce - January 15, 2024

  • Debian LTS Announce - January 22, 2024
  • Vendor Resources
  • Mozilla Security Advisory MFSA-2024-01

  • Mozilla Security Advisory MFSA-2024-02

  • Mozilla Security Advisory MFSA-2024-04
  • Related CVEs
  • CVE-2026-6773: Mozilla Firefox DOS Vulnerability

  • CVE-2026-6781: Mozilla Firefox DOS Vulnerability

  • CVE-2026-6780: Mozilla Firefox DOS Vulnerability

  • CVE-2025-9182: Mozilla Firefox DoS Vulnerability
Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the World’s Most Advanced Cybersecurity Platform

See how our intelligent, autonomous cybersecurity platform can protect your organization now and into the future.

Try SentinelOne
  • Get Started
  • Get a Demo
  • Product Tour
  • Why SentinelOne
  • Pricing & Packaging
  • FAQ
  • Contact
  • Contact Us
  • Customer Support
  • SentinelOne Status
  • Language
  • Platform
  • Singularity Platform
  • Singularity Endpoint
  • Singularity Cloud
  • Singularity AI-SIEM
  • Singularity Identity
  • Singularity Marketplace
  • Purple AI
  • Services
  • Wayfinder TDR
  • SentinelOne GO
  • Technical Account Management
  • Support Services
  • Verticals
  • Energy
  • Federal Government
  • Finance
  • Healthcare
  • Higher Education
  • K-12 Education
  • Manufacturing
  • Retail
  • State and Local Government
  • Cybersecurity for SMB
  • Resources
  • Blog
  • Labs
  • Case Studies
  • Videos
  • Product Tours
  • Events
  • Cybersecurity 101
  • eBooks
  • Webinars
  • Whitepapers
  • Press
  • News
  • Ransomware Anthology
  • Company
  • About Us
  • Our Customers
  • Careers
  • Partners
  • Legal & Compliance
  • Security & Compliance
  • Investor Relations
  • S Foundation
  • S Ventures

©2026 SentinelOne, All Rights Reserved.

Privacy Notice Terms of Use

English