Show filters
2,812 Total Results
Displaying 181-190 of 2,812
Sort by:
Attacker Value
Unknown
CVE-2024-3302
Disclosure Date: April 16, 2024 (last updated April 24, 2024)
There was no limit to the number of HTTP/2 CONTINUATION frames that would be processed. A server could abuse this to create an Out of Memory condition in the browser. This vulnerability affects Firefox < 125, Firefox ESR < 115.10, and Thunderbird < 115.10.
0
Attacker Value
Unknown
CVE-2024-31393
Disclosure Date: April 03, 2024 (last updated April 04, 2024)
Dragging Javascript URLs to the address bar could cause them to be loaded, bypassing restrictions and security protections This vulnerability affects Firefox for iOS < 124.
0
Attacker Value
Unknown
CVE-2024-31392
Disclosure Date: April 03, 2024 (last updated April 04, 2024)
If an insecure element was added to a page after a delay, Firefox would not replace the secure icon with a mixed content security status This vulnerability affects Firefox for iOS < 124.
0
Attacker Value
Unknown
CVE-2024-29944
Disclosure Date: March 22, 2024 (last updated May 02, 2024)
An attacker was able to inject an event handler into a privileged object that would allow arbitrary JavaScript execution in the parent process. Note: This vulnerability affects Desktop Firefox only, it does not affect mobile versions of Firefox. This vulnerability affects Firefox < 124.0.1 and Firefox ESR < 115.9.1.
0
Attacker Value
Unknown
CVE-2024-29943
Disclosure Date: March 22, 2024 (last updated May 02, 2024)
An attacker was able to perform an out-of-bounds read or write on a JavaScript object by fooling range-based bounds check elimination. This vulnerability affects Firefox < 124.0.1.
0
Attacker Value
Unknown
CVE-2024-2616
Disclosure Date: March 19, 2024 (last updated November 05, 2024)
To harden ICU against exploitation, the behavior for out-of-memory conditions was changed to crash instead of attempt to continue. This vulnerability affects Firefox ESR < 115.9 and Thunderbird < 115.9.
0
Attacker Value
Unknown
CVE-2024-2615
Disclosure Date: March 19, 2024 (last updated August 29, 2024)
Memory safety bugs present in Firefox 123. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 124.
0
Attacker Value
Unknown
CVE-2024-2614
Disclosure Date: March 19, 2024 (last updated August 13, 2024)
Memory safety bugs present in Firefox 123, Firefox ESR 115.8, and Thunderbird 115.8. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 124, Firefox ESR < 115.9, and Thunderbird < 115.9.
0
Attacker Value
Unknown
CVE-2024-2613
Disclosure Date: March 19, 2024 (last updated August 03, 2024)
Data was not properly sanitized when decoding a QUIC ACK frame; this could have led to unrestricted memory consumption and a crash. This vulnerability affects Firefox < 124.
0
Attacker Value
Unknown
CVE-2024-2612
Disclosure Date: March 19, 2024 (last updated August 13, 2024)
If an attacker could find a way to trigger a particular code path in `SafeRefPtr`, it could have triggered a crash or potentially be leveraged to achieve code execution. This vulnerability affects Firefox < 124, Firefox ESR < 115.9, and Thunderbird < 115.9.
0