Show filters
2,812 Total Results
Displaying 171-180 of 2,812
Sort by:
Attacker Value
Unknown

CVE-2024-3861

Disclosure Date: April 16, 2024 (last updated April 19, 2024)
If an AlignedBuffer were assigned to itself, the subsequent self-move could result in an incorrect reference count and later use-after-free. This vulnerability affects Firefox < 125, Firefox ESR < 115.10, and Thunderbird < 115.10.
0
Attacker Value
Unknown

CVE-2024-3860

Disclosure Date: April 16, 2024 (last updated April 17, 2024)
An out-of-memory condition during object initialization could result in an empty shape list. If the JIT subsequently traced the object it would crash. This vulnerability affects Firefox < 125.
0
Attacker Value
Unknown

CVE-2024-3859

Disclosure Date: April 16, 2024 (last updated April 19, 2024)
On 32-bit versions there were integer-overflows that led to an out-of-bounds-read that potentially could be triggered by a malformed OpenType font. This vulnerability affects Firefox < 125, Firefox ESR < 115.10, and Thunderbird < 115.10.
0
Attacker Value
Unknown

CVE-2024-3858

Disclosure Date: April 16, 2024 (last updated April 17, 2024)
It was possible to mutate a JavaScript object so that the JIT could crash while tracing it. This vulnerability affects Firefox < 125.
0
Attacker Value
Unknown

CVE-2024-3857

Disclosure Date: April 16, 2024 (last updated April 19, 2024)
The JIT created incorrect code for arguments in certain cases. This led to potential use-after-free crashes during garbage collection. This vulnerability affects Firefox < 125, Firefox ESR < 115.10, and Thunderbird < 115.10.
0
Attacker Value
Unknown

CVE-2024-3856

Disclosure Date: April 16, 2024 (last updated April 17, 2024)
A use-after-free could occur during WASM execution if garbage collection ran during the creation of an array. This vulnerability affects Firefox < 125.
0
Attacker Value
Unknown

CVE-2024-3855

Disclosure Date: April 16, 2024 (last updated April 17, 2024)
In certain cases the JIT incorrectly optimized MSubstr operations, which led to out-of-bounds reads. This vulnerability affects Firefox < 125.
0
Attacker Value
Unknown

CVE-2024-3854

Disclosure Date: April 16, 2024 (last updated April 19, 2024)
In some code patterns the JIT incorrectly optimized switch statements and generated code with out-of-bounds-reads. This vulnerability affects Firefox < 125, Firefox ESR < 115.10, and Thunderbird < 115.10.
0
Attacker Value
Unknown

CVE-2024-3853

Disclosure Date: April 16, 2024 (last updated April 17, 2024)
A use-after-free could result if a JavaScript realm was in the process of being initialized when a garbage collection started. This vulnerability affects Firefox < 125.
0
Attacker Value
Unknown

CVE-2024-3852

Disclosure Date: April 16, 2024 (last updated April 19, 2024)
GetBoundName could return the wrong version of an object when JIT optimizations were applied. This vulnerability affects Firefox < 125, Firefox ESR < 115.10, and Thunderbird < 115.10.
0