Show filters
1,000 Total Results
Displaying 51-60 of 1,000
Sort by:
Attacker Value
Unknown
CVE-2024-7525
Disclosure Date: August 06, 2024 (last updated August 13, 2024)
It was possible for a web extension with minimal permissions to create a `StreamFilter` which could be used to read and modify the response body of requests on any site. This vulnerability affects Firefox < 129, Firefox ESR < 115.14, Firefox ESR < 128.1, Thunderbird < 128.1, and Thunderbird < 115.14.
0
Attacker Value
Unknown
CVE-2024-7524
Disclosure Date: August 06, 2024 (last updated August 30, 2024)
Firefox adds web-compatibility shims in place of some tracking scripts blocked by Enhanced Tracking Protection. On a site protected by Content Security Policy in "strict-dynamic" mode, an attacker able to inject an HTML element could have used a DOM Clobbering attack on some of the shims and achieved XSS, bypassing the CSP strict-dynamic protection. This vulnerability affects Firefox < 129, Firefox ESR < 115.14, and Firefox ESR < 128.1.
0
Attacker Value
Unknown
CVE-2024-7522
Disclosure Date: August 06, 2024 (last updated August 13, 2024)
Editor code failed to check an attribute value. This could have led to an out-of-bounds read. This vulnerability affects Firefox < 129, Firefox ESR < 115.14, Firefox ESR < 128.1, Thunderbird < 128.1, and Thunderbird < 115.14.
0
Attacker Value
Unknown
CVE-2024-7521
Disclosure Date: August 06, 2024 (last updated August 13, 2024)
Incomplete WebAssembly exception handing could have led to a use-after-free. This vulnerability affects Firefox < 129, Firefox ESR < 115.14, Firefox ESR < 128.1, Thunderbird < 128.1, and Thunderbird < 115.14.
0
Attacker Value
Unknown
CVE-2024-7520
Disclosure Date: August 06, 2024 (last updated August 13, 2024)
A type confusion bug in WebAssembly could be leveraged by an attacker to potentially achieve code execution. This vulnerability affects Firefox < 129, Firefox ESR < 128.1, and Thunderbird < 128.1.
0
Attacker Value
Unknown
CVE-2024-7519
Disclosure Date: August 06, 2024 (last updated August 13, 2024)
Insufficient checks when processing graphics shared memory could have led to memory corruption. This could be leveraged by an attacker to perform a sandbox escape. This vulnerability affects Firefox < 129, Firefox ESR < 115.14, Firefox ESR < 128.1, Thunderbird < 128.1, and Thunderbird < 115.14.
0
Attacker Value
Unknown
CVE-2024-7518
Disclosure Date: August 06, 2024 (last updated August 20, 2024)
Select options could obscure the fullscreen notification dialog. This could be used by a malicious site to perform a spoofing attack. This vulnerability affects Firefox < 129, Firefox ESR < 128.1, and Thunderbird < 128.1.
0
Attacker Value
Unknown
CVE-2024-6604
Disclosure Date: July 09, 2024 (last updated July 16, 2024)
Memory safety bugs present in Firefox 127, Firefox ESR 115.12, and Thunderbird 115.12. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 128, Firefox ESR < 115.13, Thunderbird < 115.13, and Thunderbird < 128.
0
Attacker Value
Unknown
CVE-2024-6603
Disclosure Date: July 09, 2024 (last updated July 16, 2024)
In an out-of-memory scenario an allocation could fail but free would have been called on the pointer afterwards leading to memory corruption. This vulnerability affects Firefox < 128, Firefox ESR < 115.13, Thunderbird < 115.13, and Thunderbird < 128.
0
Attacker Value
Unknown
CVE-2024-6602
Disclosure Date: July 09, 2024 (last updated November 26, 2024)
A mismatch between allocator and deallocator could have led to memory corruption. This vulnerability affects Firefox < 128, Firefox ESR < 115.13, Thunderbird < 115.13, and Thunderbird < 128.
0