Show filters
1,501 Total Results
Displaying 101-110 of 1,501
Sort by:
Attacker Value
Unknown
CVE-2023-6207
Disclosure Date: November 21, 2023 (last updated November 29, 2023)
Ownership mismanagement led to a use-after-free in ReadableByteStreams This vulnerability affects Firefox < 120, Firefox ESR < 115.5.0, and Thunderbird < 115.5.
0
Attacker Value
Unknown
CVE-2023-6206
Disclosure Date: November 21, 2023 (last updated November 29, 2023)
The black fade animation when exiting fullscreen is roughly the length of the anti-clickjacking delay on permission prompts. It was possible to use this fact to surprise users by luring them to click where the permission grant button would be about to appear. This vulnerability affects Firefox < 120, Firefox ESR < 115.5.0, and Thunderbird < 115.5.
0
Attacker Value
Unknown
CVE-2023-6205
Disclosure Date: November 21, 2023 (last updated November 29, 2023)
It was possible to cause the use of a MessagePort after it had already been freed, which could potentially have led to an exploitable crash. This vulnerability affects Firefox < 120, Firefox ESR < 115.5.0, and Thunderbird < 115.5.
0
Attacker Value
Unknown
CVE-2023-6204
Disclosure Date: November 21, 2023 (last updated November 29, 2023)
On some systems—depending on the graphics settings and drivers—it was possible to force an out-of-bounds read and leak memory data into the images created on the canvas element. This vulnerability affects Firefox < 120, Firefox ESR < 115.5.0, and Thunderbird < 115.5.
0
Attacker Value
Unknown
CVE-2023-6112
Disclosure Date: November 15, 2023 (last updated January 27, 2024)
Use after free in Navigation in Google Chrome prior to 119.0.6045.159 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
0
Attacker Value
Unknown
CVE-2023-5997
Disclosure Date: November 15, 2023 (last updated January 27, 2024)
Use after free in Garbage Collection in Google Chrome prior to 119.0.6045.159 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
0
Attacker Value
Unknown
CVE-2023-23583
Disclosure Date: November 14, 2023 (last updated November 29, 2023)
Sequence of processor instructions leads to unexpected behavior for some Intel(R) Processors may allow an authenticated user to potentially enable escalation of privilege and/or information disclosure and/or denial of service via local access.
0
Attacker Value
Unknown
CVE-2023-5996
Disclosure Date: November 08, 2023 (last updated November 16, 2023)
Use after free in WebAudio in Google Chrome prior to 119.0.6045.123 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
0
Attacker Value
Unknown
CVE-2023-47272
Disclosure Date: November 06, 2023 (last updated December 29, 2023)
Roundcube 1.5.x before 1.5.6 and 1.6.x before 1.6.5 allows XSS via a Content-Type or Content-Disposition header (used for attachment preview or download).
0
Attacker Value
Unknown
CVE-2023-5859
Disclosure Date: November 01, 2023 (last updated December 14, 2023)
Incorrect security UI in Picture In Picture in Google Chrome prior to 119.0.6045.105 allowed a remote attacker to perform domain spoofing via a crafted local HTML page. (Chromium security severity: Low)
0