Show filters
2,812 Total Results
Displaying 61-70 of 2,812
Sort by:
Attacker Value
Unknown
CVE-2024-10466
Disclosure Date: October 29, 2024 (last updated November 05, 2024)
By sending a specially crafted push message, a remote server could have hung the parent process, causing the browser to become unresponsive. This vulnerability affects Firefox < 132, Firefox ESR < 128.4, Thunderbird < 128.4, and Thunderbird < 132.
0
Attacker Value
Unknown
CVE-2024-10465
Disclosure Date: October 29, 2024 (last updated November 05, 2024)
A clipboard "paste" button could persist across tabs which allowed a spoofing attack. This vulnerability affects Firefox < 132, Firefox ESR < 128.4, Thunderbird < 128.4, and Thunderbird < 132.
0
Attacker Value
Unknown
CVE-2024-10464
Disclosure Date: October 29, 2024 (last updated November 05, 2024)
Repeated writes to history interface attributes could have been used to cause a Denial of Service condition in the browser. This was addressed by introducing rate-limiting to this API. This vulnerability affects Firefox < 132, Firefox ESR < 128.4, Thunderbird < 128.4, and Thunderbird < 132.
0
Attacker Value
Unknown
CVE-2024-10463
Disclosure Date: October 29, 2024 (last updated November 05, 2024)
Video frames could have been leaked between origins in some situations. This vulnerability affects Firefox < 132, Firefox ESR < 128.4, Firefox ESR < 115.17, Thunderbird < 128.4, and Thunderbird < 132.
0
Attacker Value
Unknown
CVE-2024-10462
Disclosure Date: October 29, 2024 (last updated November 05, 2024)
Truncation of a long URL could have allowed origin spoofing in a permission prompt. This vulnerability affects Firefox < 132, Firefox ESR < 128.4, Thunderbird < 128.4, and Thunderbird < 132.
0
Attacker Value
Unknown
CVE-2024-10461
Disclosure Date: October 29, 2024 (last updated November 05, 2024)
In multipart/x-mixed-replace responses, `Content-Disposition: attachment` in the response header was not respected and did not force a download, which could allow XSS attacks. This vulnerability affects Firefox < 132, Firefox ESR < 128.4, Thunderbird < 128.4, and Thunderbird < 132.
0
Attacker Value
Unknown
CVE-2024-10460
Disclosure Date: October 29, 2024 (last updated November 01, 2024)
The origin of an external protocol handler prompt could have been obscured using a data: URL within an `iframe`. This vulnerability affects Firefox < 132, Firefox ESR < 128.4, Thunderbird < 128.4, and Thunderbird < 132.
0
Attacker Value
Unknown
CVE-2024-10459
Disclosure Date: October 29, 2024 (last updated November 01, 2024)
An attacker could have caused a use-after-free when accessibility was enabled, leading to a potentially exploitable crash. This vulnerability affects Firefox < 132, Firefox ESR < 128.4, Firefox ESR < 115.17, Thunderbird < 128.4, and Thunderbird < 132.
0
Attacker Value
Unknown
CVE-2024-10458
Disclosure Date: October 29, 2024 (last updated November 01, 2024)
A permission leak could have occurred from a trusted site to an untrusted site via `embed` or `object` elements. This vulnerability affects Firefox < 132, Firefox ESR < 128.4, Firefox ESR < 115.17, Thunderbird < 128.4, and Thunderbird < 132.
0
Attacker Value
Unknown
CVE-2024-10004
Disclosure Date: October 15, 2024 (last updated October 16, 2024)
Opening an external link to an HTTP website when Firefox iOS was previously closed and had an HTTPS tab open could in some cases result in the padlock icon showing an HTTPS indicator incorrectly This vulnerability affects Firefox for iOS < 131.2.
0