Show filters
3,162 Total Results
Displaying 171-180 of 3,162
Sort by:
Attacker Value
Unknown

CVE-2024-4766

Disclosure Date: May 14, 2024 (last updated November 26, 2024)
Different techniques existed to obscure the fullscreen notification in Firefox for Android. These could have led to potential user confusion and spoofing attacks. *This bug only affects Firefox for Android. Other versions of Firefox are unaffected.* This vulnerability affects Firefox < 126.
0
Attacker Value
Unknown

CVE-2024-4765

Disclosure Date: May 14, 2024 (last updated May 15, 2024)
Web application manifests were stored by using an insecure MD5 hash which allowed for a hash collision to overwrite another application's manifest. This could have been exploited to run arbitrary code in another application's context. *This issue only affects Firefox for Android. Other versions of Firefox are unaffected.* This vulnerability affects Firefox < 126.
0
Attacker Value
Unknown

CVE-2024-4764

Disclosure Date: May 14, 2024 (last updated May 15, 2024)
Multiple WebRTC threads could have claimed a newly connected audio input leading to use-after-free. This vulnerability affects Firefox < 126.
0
Attacker Value
Unknown

CVE-2024-4367

Disclosure Date: May 14, 2024 (last updated January 23, 2025)
A type check was missing when handling fonts in PDF.js, which would allow arbitrary JavaScript execution in the PDF.js context. This vulnerability affects Firefox < 126, Firefox ESR < 115.11, and Thunderbird < 115.11.
Attacker Value
Unknown

CVE-2024-3865

Disclosure Date: April 16, 2024 (last updated April 17, 2024)
Memory safety bugs present in Firefox 124. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 125.
0
Attacker Value
Unknown

CVE-2024-3864

Disclosure Date: April 16, 2024 (last updated April 24, 2024)
Memory safety bug present in Firefox 124, Firefox ESR 115.9, and Thunderbird 115.9. This bug showed evidence of memory corruption and we presume that with enough effort this could have been exploited to run arbitrary code. This vulnerability affects Firefox < 125, Firefox ESR < 115.10, and Thunderbird < 115.10.
0
Attacker Value
Unknown

CVE-2024-3863

Disclosure Date: April 16, 2024 (last updated January 22, 2025)
The executable file warning was not presented when downloading .xrm-ms files. *Note: This issue only affected Windows operating systems. Other operating systems are unaffected.* This vulnerability affects Firefox < 125, Firefox ESR < 115.10, and Thunderbird < 115.10.
Attacker Value
Unknown

CVE-2024-3862

Disclosure Date: April 16, 2024 (last updated April 17, 2024)
The MarkStack assignment operator, part of the JavaScript engine, could access uninitialized memory if it were used in a self-assignment. This vulnerability affects Firefox < 125.
0
Attacker Value
Unknown

CVE-2024-3861

Disclosure Date: April 16, 2024 (last updated April 19, 2024)
If an AlignedBuffer were assigned to itself, the subsequent self-move could result in an incorrect reference count and later use-after-free. This vulnerability affects Firefox < 125, Firefox ESR < 115.10, and Thunderbird < 115.10.
0
Attacker Value
Unknown

CVE-2024-3860

Disclosure Date: April 16, 2024 (last updated April 17, 2024)
An out-of-memory condition during object initialization could result in an empty shape list. If the JIT subsequently traced the object it would crash. This vulnerability affects Firefox < 125.
0