Show filters
3,162 Total Results
Displaying 181-190 of 3,162
Sort by:
Attacker Value
Unknown
CVE-2024-3859
Disclosure Date: April 16, 2024 (last updated April 19, 2024)
On 32-bit versions there were integer-overflows that led to an out-of-bounds-read that potentially could be triggered by a malformed OpenType font. This vulnerability affects Firefox < 125, Firefox ESR < 115.10, and Thunderbird < 115.10.
0
Attacker Value
Unknown
CVE-2024-3858
Disclosure Date: April 16, 2024 (last updated April 17, 2024)
It was possible to mutate a JavaScript object so that the JIT could crash while tracing it. This vulnerability affects Firefox < 125.
0
Attacker Value
Unknown
CVE-2024-3857
Disclosure Date: April 16, 2024 (last updated April 19, 2024)
The JIT created incorrect code for arguments in certain cases. This led to potential use-after-free crashes during garbage collection. This vulnerability affects Firefox < 125, Firefox ESR < 115.10, and Thunderbird < 115.10.
0
Attacker Value
Unknown
CVE-2024-3856
Disclosure Date: April 16, 2024 (last updated April 17, 2024)
A use-after-free could occur during WASM execution if garbage collection ran during the creation of an array. This vulnerability affects Firefox < 125.
0
Attacker Value
Unknown
CVE-2024-3855
Disclosure Date: April 16, 2024 (last updated April 17, 2024)
In certain cases the JIT incorrectly optimized MSubstr operations, which led to out-of-bounds reads. This vulnerability affects Firefox < 125.
0
Attacker Value
Unknown
CVE-2024-3854
Disclosure Date: April 16, 2024 (last updated April 19, 2024)
In some code patterns the JIT incorrectly optimized switch statements and generated code with out-of-bounds-reads. This vulnerability affects Firefox < 125, Firefox ESR < 115.10, and Thunderbird < 115.10.
0
Attacker Value
Unknown
CVE-2024-3853
Disclosure Date: April 16, 2024 (last updated April 17, 2024)
A use-after-free could result if a JavaScript realm was in the process of being initialized when a garbage collection started. This vulnerability affects Firefox < 125.
0
Attacker Value
Unknown
CVE-2024-3852
Disclosure Date: April 16, 2024 (last updated April 19, 2024)
GetBoundName could return the wrong version of an object when JIT optimizations were applied. This vulnerability affects Firefox < 125, Firefox ESR < 115.10, and Thunderbird < 115.10.
0
Attacker Value
Unknown
CVE-2024-3302
Disclosure Date: April 16, 2024 (last updated April 24, 2024)
There was no limit to the number of HTTP/2 CONTINUATION frames that would be processed. A server could abuse this to create an Out of Memory condition in the browser. This vulnerability affects Firefox < 125, Firefox ESR < 115.10, and Thunderbird < 115.10.
0
Attacker Value
Unknown
CVE-2024-31393
Disclosure Date: April 03, 2024 (last updated April 04, 2024)
Dragging Javascript URLs to the address bar could cause them to be loaded, bypassing restrictions and security protections This vulnerability affects Firefox for iOS < 124.
0