Search CVE reports


Toggle filters

891 – 900 of 3420 results


CVE-2024-0752

Medium priority
Not affected

A use-after-free crash could have occurred on macOS if a Firefox update were being applied on a very busy system. This could have resulted in an exploitable crash. This vulnerability affects Firefox < 122.

8 affected packages

firefox, mozjs102, mozjs38, mozjs52, mozjs68...

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox — — Not affected Not in release Ignored
mozjs102 — — Not affected Not in release Not in release
mozjs38 — — Not in release Not in release Not affected
mozjs52 — — Not in release Not affected Not affected
mozjs68 — — Not in release Not affected Not in release
mozjs78 — — Not affected Not in release Not in release
mozjs91 — — Not affected Not in release Not in release
thunderbird — — Not affected Not in release Ignored
Show all 8 packages Show less packages

CVE-2024-0751

Low priority

Some fixes available 4 of 17

A malicious devtools extension could have been used to escalate privileges. This vulnerability affects Firefox < 122, Firefox ESR < 115.7, and Thunderbird < 115.7.

8 affected packages

firefox, mozjs102, mozjs38, mozjs52, mozjs68...

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox — Not affected Not affected Fixed Ignored
mozjs102 — Ignored Ignored Not in release Not in release
mozjs38 — Not in release Not in release Not in release Ignored
mozjs52 — Not in release Not in release Ignored Ignored
mozjs68 — Not in release Not in release Ignored Not in release
mozjs78 — Not in release Ignored Not in release Not in release
mozjs91 — Not in release Ignored Not in release Not in release
thunderbird — Not affected Fixed Fixed Ignored
Show all 8 packages Show less packages

CVE-2024-0750

Medium priority

Some fixes available 4 of 17

A bug in popup notifications delay calculation could have made it possible for an attacker to trick a user into granting permissions. This vulnerability affects Firefox < 122, Firefox ESR < 115.7, and Thunderbird < 115.7.

8 affected packages

firefox, mozjs102, mozjs38, mozjs52, mozjs68...

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox — Not affected Not affected Fixed Ignored
mozjs102 — Ignored Ignored Not in release Not in release
mozjs38 — Not in release Not in release Not in release Ignored
mozjs52 — Not in release Not in release Ignored Ignored
mozjs68 — Not in release Not in release Ignored Not in release
mozjs78 — Not in release Ignored Not in release Not in release
mozjs91 — Not in release Ignored Not in release Not in release
thunderbird — Not affected Fixed Fixed Ignored
Show all 8 packages Show less packages

CVE-2024-0749

Medium priority

Some fixes available 4 of 17

A phishing site could have repurposed an `about:` dialog to show phishing content with an incorrect origin in the address bar. This vulnerability affects Firefox < 122 and Thunderbird < 115.7.

8 affected packages

firefox, mozjs102, mozjs38, mozjs52, mozjs68...

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox — Not affected Not affected Fixed Ignored
mozjs102 — Ignored Ignored Not in release Not in release
mozjs38 — Not in release Not in release Not in release Ignored
mozjs52 — Not in release Not in release Ignored Ignored
mozjs68 — Not in release Not in release Ignored Not in release
mozjs78 — Not in release Ignored Not in release Not in release
mozjs91 — Not in release Ignored Not in release Not in release
thunderbird — Not affected Fixed Fixed Ignored
Show all 8 packages Show less packages

CVE-2024-0748

Medium priority

Some fixes available 1 of 14

A compromised content process could have updated the document URI. This could have allowed an attacker to set an arbitrary URI in the address bar or history. This vulnerability affects Firefox < 122.

8 affected packages

firefox, mozjs102, mozjs38, mozjs52, mozjs68...

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox — Not affected Not affected Fixed Ignored
mozjs102 — Ignored Ignored Not in release Not in release
mozjs38 — Not in release Not in release Not in release Ignored
mozjs52 — Not in release Not in release Ignored Ignored
mozjs68 — Not in release Not in release Ignored Not in release
mozjs78 — Not in release Ignored Not in release Not in release
mozjs91 — Not in release Ignored Not in release Not in release
thunderbird — Not affected Not affected Not in release Ignored
Show all 8 packages Show less packages

CVE-2024-0747

Medium priority

Some fixes available 4 of 17

When a parent page loaded a child in an iframe with `unsafe-inline`, the parent Content Security Policy could have overridden the child Content Security Policy. This vulnerability affects Firefox < 122, Firefox ESR < 115.7, and...

8 affected packages

firefox, mozjs102, mozjs38, mozjs52, mozjs68...

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox — Not affected Not affected Fixed Ignored
mozjs102 — Ignored Ignored Not in release Not in release
mozjs38 — Not in release Not in release Not in release Ignored
mozjs52 — Not in release Not in release Ignored Ignored
mozjs68 — Not in release Not in release Ignored Not in release
mozjs78 — Not in release Ignored Not in release Not in release
mozjs91 — Not in release Ignored Not in release Not in release
thunderbird — Not affected Fixed Fixed Ignored
Show all 8 packages Show less packages

CVE-2024-0746

Low priority

Some fixes available 4 of 17

A Linux user opening the print preview dialog could have caused the browser to crash. This vulnerability affects Firefox < 122, Firefox ESR < 115.7, and Thunderbird < 115.7.

8 affected packages

firefox, mozjs102, mozjs38, mozjs52, mozjs68...

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox — Not affected Not affected Fixed Ignored
mozjs102 — Ignored Ignored Not in release Not in release
mozjs38 — Not in release Not in release Not in release Ignored
mozjs52 — Not in release Not in release Ignored Ignored
mozjs68 — Not in release Not in release Ignored Not in release
mozjs78 — Not in release Ignored Not in release Not in release
mozjs91 — Not in release Ignored Not in release Not in release
thunderbird — Not affected Fixed Fixed Ignored
Show all 8 packages Show less packages

CVE-2024-0745

Medium priority

Some fixes available 1 of 14

The WebAudio `OscillatorNode` object was susceptible to a stack buffer overflow. This could have led to a potentially exploitable crash. This vulnerability affects Firefox < 122.

8 affected packages

firefox, mozjs102, mozjs38, mozjs52, mozjs68...

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox — Not affected Not affected Fixed Ignored
mozjs102 — Ignored Ignored Not in release Not in release
mozjs38 — Not in release Not in release Not in release Ignored
mozjs52 — Not in release Not in release Ignored Ignored
mozjs68 — Not in release Not in release Ignored Not in release
mozjs78 — Not in release Ignored Not in release Not in release
mozjs91 — Not in release Ignored Not in release Not in release
thunderbird — Not affected Not affected Not in release Ignored
Show all 8 packages Show less packages

CVE-2024-0744

Medium priority

Some fixes available 1 of 14

In some circumstances, JIT compiled code could have dereferenced a wild pointer value. This could have led to an exploitable crash. This vulnerability affects Firefox < 122.

8 affected packages

firefox, mozjs102, mozjs38, mozjs52, mozjs68...

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox — Not affected Not affected Fixed Ignored
mozjs102 — Ignored Ignored Not in release Not in release
mozjs38 — Not in release Not in release Not in release Ignored
mozjs52 — Not in release Not in release Ignored Ignored
mozjs68 — Not in release Not in release Ignored Not in release
mozjs78 — Not in release Ignored Not in release Not in release
mozjs91 — Not in release Ignored Not in release Not in release
thunderbird — Not affected Not affected Not in release Ignored
Show all 8 packages Show less packages

CVE-2024-0743

Medium priority

Some fixes available 4 of 17

An unchecked return value in TLS handshake code could have caused a potentially exploitable crash. This vulnerability affects Firefox < 122, Firefox ESR < 115.9, and Thunderbird < 115.9.

8 affected packages

firefox, mozjs102, mozjs38, mozjs52, mozjs68...

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox — Not affected Not affected Fixed Ignored
mozjs102 — Ignored Ignored Not in release Not in release
mozjs38 — Not in release Not in release Not in release Ignored
mozjs52 — Not in release Not in release Ignored Ignored
mozjs68 — Not in release Not in release Ignored Not in release
mozjs78 — Not in release Ignored Not in release Not in release
mozjs91 — Not in release Ignored Not in release Not in release
thunderbird — Not affected Fixed Fixed Ignored
Show all 8 packages Show less packages