Show filters
3,616 Total Results
Displaying 241-250 of 3,616
Sort by:
Attacker Value
Unknown

CVE-2023-6206

Disclosure Date: November 21, 2023 (last updated February 25, 2025)
The black fade animation when exiting fullscreen is roughly the length of the anti-clickjacking delay on permission prompts. It was possible to use this fact to surprise users by luring them to click where the permission grant button would be about to appear. This vulnerability affects Firefox < 120, Firefox ESR < 115.5.0, and Thunderbird < 115.5.
Attacker Value
Unknown

CVE-2023-6205

Disclosure Date: November 21, 2023 (last updated February 25, 2025)
It was possible to cause the use of a MessagePort after it had already been freed, which could potentially have led to an exploitable crash. This vulnerability affects Firefox < 120, Firefox ESR < 115.5.0, and Thunderbird < 115.5.
Attacker Value
Unknown

CVE-2023-6204

Disclosure Date: November 21, 2023 (last updated February 25, 2025)
On some systems—depending on the graphics settings and drivers—it was possible to force an out-of-bounds read and leak memory data into the images created on the canvas element. This vulnerability affects Firefox < 120, Firefox ESR < 115.5.0, and Thunderbird < 115.5.
Attacker Value
Unknown

CVE-2023-23583

Disclosure Date: November 14, 2023 (last updated February 25, 2025)
Sequence of processor instructions leads to unexpected behavior for some Intel(R) Processors may allow an authenticated user to potentially enable escalation of privilege and/or information disclosure and/or denial of service via local access.
Attacker Value
Unknown

CVE-2023-47272

Disclosure Date: November 06, 2023 (last updated February 25, 2025)
Roundcube 1.5.x before 1.5.6 and 1.6.x before 1.6.5 allows XSS via a Content-Type or Content-Disposition header (used for attachment preview or download).
Attacker Value
Unknown

CVE-2023-34059

Disclosure Date: October 27, 2023 (last updated November 08, 2023)
open-vm-tools contains a file descriptor hijack vulnerability in the vmware-user-suid-wrapper. A malicious actor with non-root privileges may be able to hijack the /dev/uinput file descriptor allowing them to simulate user inputs.
Attacker Value
Unknown

CVE-2023-34058

Disclosure Date: October 27, 2023 (last updated February 25, 2025)
VMware Tools contains a SAML token signature bypass vulnerability. A malicious actor that has been granted Guest Operation Privileges https://docs.vmware.com/en/VMware-vSphere/8.0/vsphere-security/GUID-6A952214-0E5E-4CCF-9D2A-90948FF643EC.html  in a target virtual machine may be able to elevate their privileges if that target virtual machine has been assigned a more privileged Guest Alias https://vdc-download.vmware.com/vmwb-repository/dcr-public/d1902b0e-d479-46bf-8ac9-cee0e31e8ec0/07ce8dbd-db48-4261-9b8f-c6d3ad8ba472/vim.vm.guest.AliasManager.html .
Attacker Value
Unknown

CVE-2023-5732

Disclosure Date: October 25, 2023 (last updated November 02, 2023)
An attacker could have created a malicious link using bidirectional characters to spoof the location in the address bar when visited. This vulnerability affects Firefox < 117, Firefox ESR < 115.4, and Thunderbird < 115.4.1.
Attacker Value
Unknown

CVE-2023-5730

Disclosure Date: October 25, 2023 (last updated February 25, 2025)
Memory safety bugs present in Firefox 118, Firefox ESR 115.3, and Thunderbird 115.3. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 119, Firefox ESR < 115.4, and Thunderbird < 115.4.1.
Attacker Value
Unknown

CVE-2023-5728

Disclosure Date: October 25, 2023 (last updated February 25, 2025)
During garbage collection extra operations were performed on a object that should not be. This could have led to a potentially exploitable crash. This vulnerability affects Firefox < 119, Firefox ESR < 115.4, and Thunderbird < 115.4.1.