Show filters
3,162 Total Results
Displaying 181-190 of 3,162
Sort by:
Attacker Value
Unknown

CVE-2024-3859

Disclosure Date: April 16, 2024 (last updated April 19, 2024)
On 32-bit versions there were integer-overflows that led to an out-of-bounds-read that potentially could be triggered by a malformed OpenType font. This vulnerability affects Firefox < 125, Firefox ESR < 115.10, and Thunderbird < 115.10.
0
Attacker Value
Unknown

CVE-2024-3858

Disclosure Date: April 16, 2024 (last updated April 17, 2024)
It was possible to mutate a JavaScript object so that the JIT could crash while tracing it. This vulnerability affects Firefox < 125.
0
Attacker Value
Unknown

CVE-2024-3857

Disclosure Date: April 16, 2024 (last updated April 19, 2024)
The JIT created incorrect code for arguments in certain cases. This led to potential use-after-free crashes during garbage collection. This vulnerability affects Firefox < 125, Firefox ESR < 115.10, and Thunderbird < 115.10.
0
Attacker Value
Unknown

CVE-2024-3856

Disclosure Date: April 16, 2024 (last updated April 17, 2024)
A use-after-free could occur during WASM execution if garbage collection ran during the creation of an array. This vulnerability affects Firefox < 125.
0
Attacker Value
Unknown

CVE-2024-3855

Disclosure Date: April 16, 2024 (last updated April 17, 2024)
In certain cases the JIT incorrectly optimized MSubstr operations, which led to out-of-bounds reads. This vulnerability affects Firefox < 125.
0
Attacker Value
Unknown

CVE-2024-3854

Disclosure Date: April 16, 2024 (last updated April 19, 2024)
In some code patterns the JIT incorrectly optimized switch statements and generated code with out-of-bounds-reads. This vulnerability affects Firefox < 125, Firefox ESR < 115.10, and Thunderbird < 115.10.
0
Attacker Value
Unknown

CVE-2024-3853

Disclosure Date: April 16, 2024 (last updated April 17, 2024)
A use-after-free could result if a JavaScript realm was in the process of being initialized when a garbage collection started. This vulnerability affects Firefox < 125.
0
Attacker Value
Unknown

CVE-2024-3852

Disclosure Date: April 16, 2024 (last updated April 19, 2024)
GetBoundName could return the wrong version of an object when JIT optimizations were applied. This vulnerability affects Firefox < 125, Firefox ESR < 115.10, and Thunderbird < 115.10.
0
Attacker Value
Unknown

CVE-2024-3302

Disclosure Date: April 16, 2024 (last updated April 24, 2024)
There was no limit to the number of HTTP/2 CONTINUATION frames that would be processed. A server could abuse this to create an Out of Memory condition in the browser. This vulnerability affects Firefox < 125, Firefox ESR < 115.10, and Thunderbird < 115.10.
0
Attacker Value
Unknown

CVE-2024-31393

Disclosure Date: April 03, 2024 (last updated April 04, 2024)
Dragging Javascript URLs to the address bar could cause them to be loaded, bypassing restrictions and security protections This vulnerability affects Firefox for iOS < 124.
0