Show filters
2,812 Total Results
Displaying 161-170 of 2,812
Sort by:
Attacker Value
Unknown

CVE-2024-4767

Disclosure Date: May 14, 2024 (last updated May 15, 2024)
If the `browser.privatebrowsing.autostart` preference is enabled, IndexedDB files were not properly deleted when the window was closed. This preference is disabled by default in Firefox. This vulnerability affects Firefox < 126, Firefox ESR < 115.11, and Thunderbird < 115.11.
0
Attacker Value
Unknown

CVE-2024-4766

Disclosure Date: May 14, 2024 (last updated November 26, 2024)
Different techniques existed to obscure the fullscreen notification in Firefox for Android. These could have led to potential user confusion and spoofing attacks. *This bug only affects Firefox for Android. Other versions of Firefox are unaffected.* This vulnerability affects Firefox < 126.
0
Attacker Value
Unknown

CVE-2024-4765

Disclosure Date: May 14, 2024 (last updated May 15, 2024)
Web application manifests were stored by using an insecure MD5 hash which allowed for a hash collision to overwrite another application's manifest. This could have been exploited to run arbitrary code in another application's context. *This issue only affects Firefox for Android. Other versions of Firefox are unaffected.* This vulnerability affects Firefox < 126.
0
Attacker Value
Unknown

CVE-2024-4764

Disclosure Date: May 14, 2024 (last updated May 15, 2024)
Multiple WebRTC threads could have claimed a newly connected audio input leading to use-after-free. This vulnerability affects Firefox < 126.
0
Attacker Value
Unknown

CVE-2024-4367

Disclosure Date: May 14, 2024 (last updated January 23, 2025)
A type check was missing when handling fonts in PDF.js, which would allow arbitrary JavaScript execution in the PDF.js context. This vulnerability affects Firefox < 126, Firefox ESR < 115.11, and Thunderbird < 115.11.
Attacker Value
Unknown

CVE-2024-32986

Disclosure Date: May 03, 2024 (last updated May 03, 2024)
PWAsForFirefox is a tool to install, manage and use Progressive Web Apps (PWAs) in Mozilla Firefox. Due to improper sanitization of web app properties (such as name, description, shortcuts), web apps were able to inject additional lines into XDG Desktop Entries (on Linux) and `AppInfo.ini` (on PortableApps.com). This allowed malicious web apps to introduce keys like `Exec`, which could run arbitrary code when the affected web app was launched. This vulnerability affects all Linux and PortableApps.com users of all PWAsForFirefox versions up to (excluding) 2.12.0. Windows and macOS users are not affected. This vulnerability has been fixed in commit `9932d4b` which has been included in release in v2.12.0. The main fix is implemented in the native part, but the extension also contains additional fixes. All Linux and PortableApps.com users are advised to update to this version as soon as possible. It is also recommended for Windows and macOS users to update to this version, as it contains …
0
Attacker Value
Unknown

CVE-2024-3865

Disclosure Date: April 16, 2024 (last updated April 17, 2024)
Memory safety bugs present in Firefox 124. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 125.
0
Attacker Value
Unknown

CVE-2024-3864

Disclosure Date: April 16, 2024 (last updated April 24, 2024)
Memory safety bug present in Firefox 124, Firefox ESR 115.9, and Thunderbird 115.9. This bug showed evidence of memory corruption and we presume that with enough effort this could have been exploited to run arbitrary code. This vulnerability affects Firefox < 125, Firefox ESR < 115.10, and Thunderbird < 115.10.
0
Attacker Value
Unknown

CVE-2024-3863

Disclosure Date: April 16, 2024 (last updated January 22, 2025)
The executable file warning was not presented when downloading .xrm-ms files. *Note: This issue only affected Windows operating systems. Other operating systems are unaffected.* This vulnerability affects Firefox < 125, Firefox ESR < 115.10, and Thunderbird < 115.10.
Attacker Value
Unknown

CVE-2024-3862

Disclosure Date: April 16, 2024 (last updated April 17, 2024)
The MarkStack assignment operator, part of the JavaScript engine, could access uninitialized memory if it were used in a self-assignment. This vulnerability affects Firefox < 125.
0