Show filters
2,812 Total Results
Displaying 211-220 of 2,812
Sort by:
Attacker Value
Unknown

CVE-2024-1550

Disclosure Date: February 20, 2024 (last updated December 21, 2024)
A malicious website could have used a combination of exiting fullscreen mode and `requestPointerLock` to cause the user's mouse to be re-positioned unexpectedly, which could have led to user confusion and inadvertently granting permissions they did not intend to grant. This vulnerability affects Firefox < 123, Firefox ESR < 115.8, and Thunderbird < 115.8.
Attacker Value
Unknown

CVE-2024-1549

Disclosure Date: February 20, 2024 (last updated February 21, 2024)
If a website set a large custom cursor, portions of the cursor could have overlapped with the permission dialog, potentially resulting in user confusion and unexpected granted permissions. This vulnerability affects Firefox < 123, Firefox ESR < 115.8, and Thunderbird < 115.8.
0
Attacker Value
Unknown

CVE-2024-1547

Disclosure Date: February 20, 2024 (last updated December 21, 2024)
Through a series of API calls and redirects, an attacker-controlled alert dialog could have been displayed on another website (with the victim website's URL shown). This vulnerability affects Firefox < 123, Firefox ESR < 115.8, and Thunderbird < 115.8.
Attacker Value
Unknown

CVE-2024-1546

Disclosure Date: February 20, 2024 (last updated February 21, 2024)
When storing and re-accessing data on a networking channel, the length of buffers may have been confused, resulting in an out-of-bounds memory read. This vulnerability affects Firefox < 123, Firefox ESR < 115.8, and Thunderbird < 115.8.
0
Attacker Value
Unknown

CVE-2024-0953

Disclosure Date: February 05, 2024 (last updated August 06, 2024)
When a user scans a QR Code with the QR Code Scanner feature, the user is not prompted before being navigated to the page specified in the code. This may surprise the user and potentially direct them to unwanted content. This vulnerability affects Firefox for iOS < 129.
Attacker Value
Unknown

CVE-2024-0755

Disclosure Date: January 23, 2024 (last updated January 30, 2024)
Memory safety bugs present in Firefox 121, Firefox ESR 115.6, and Thunderbird 115.6. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 122, Firefox ESR < 115.7, and Thunderbird < 115.7.
Attacker Value
Unknown

CVE-2024-0754

Disclosure Date: January 23, 2024 (last updated January 31, 2024)
Some WASM source files could have caused a crash when loaded in devtools. This vulnerability affects Firefox < 122.
Attacker Value
Unknown

CVE-2024-0753

Disclosure Date: January 23, 2024 (last updated January 31, 2024)
In specific HSTS configurations an attacker could have bypassed HSTS on a subdomain. This vulnerability affects Firefox < 122, Firefox ESR < 115.7, and Thunderbird < 115.7.
Attacker Value
Unknown

CVE-2024-0752

Disclosure Date: January 23, 2024 (last updated January 31, 2024)
A use-after-free crash could have occurred on macOS if a Firefox update were being applied on a very busy system. This could have resulted in an exploitable crash. This vulnerability affects Firefox < 122.
Attacker Value
Unknown

CVE-2024-0751

Disclosure Date: January 23, 2024 (last updated January 31, 2024)
A malicious devtools extension could have been used to escalate privileges. This vulnerability affects Firefox < 122, Firefox ESR < 115.7, and Thunderbird < 115.7.