Search CVE reports


Toggle filters

731 – 740 of 3420 results


CVE-2024-11691

Medium priority
Fixed

Certain WebGL operations on Apple silicon M series devices could have lead to an out-of-bounds write and memory corruption due to a flaw in Apple's GPU driver. *This bug only affected the application on Apple M series hardware....

2 affected packages

firefox, thunderbird

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox — Not affected Not affected Not in release —
thunderbird — Not affected Fixed Fixed —
Show less packages

CVE-2024-50336

Medium priority

Some fixes available 1 of 13

matrix-js-sdk is a Matrix messaging protocol Client-Server SDK for JavaScript. matrix-js-sdk before 34.11.0 is vulnerable to client-side path traversal via crafted MXC URIs. A malicious room member can trigger clients based on the...

10 affected packages

firefox, mozjs102, mozjs115, mozjs38, mozjs52...

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox Not affected Not affected Not affected — —
mozjs102 Not in release Ignored Ignored — —
mozjs115 Not in release Ignored Not in release — —
mozjs38 Not in release Not in release Not in release — Needs evaluation
mozjs52 Not in release Not in release Not in release Ignored Ignored
mozjs68 Not in release Not in release Not in release Ignored —
mozjs78 Not in release Not in release Ignored — —
mozjs91 Not in release Not in release Ignored — —
node-matrix-js-sdk Not in release Needs evaluation Needs evaluation Ignored —
thunderbird Not affected Not affected Fixed — —
Show all 10 packages Show less packages

CVE-2024-10941

Medium priority
Fixed

A malicious website could have included an iframe with an malformed URI resulting in a non-exploitable browser crash. This vulnerability affects Firefox < 126.

2 affected packages

firefox, thunderbird

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox — Not affected Not affected Fixed —
thunderbird — Not affected Not affected Not in release —
Show less packages

CVE-2024-10468

Medium priority

Some fixes available 2 of 13

Potential race conditions in IndexedDB could have caused memory corruption, leading to a potentially exploitable crash. This vulnerability affects Firefox < 132 and Thunderbird < 132.

9 affected packages

firefox, mozjs102, mozjs115, mozjs38, mozjs52...

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox Not affected Not affected Not affected Fixed —
mozjs102 Not in release Ignored Ignored Not in release —
mozjs115 Not in release Ignored Not in release Not in release —
mozjs38 Not in release Not in release Not in release Not in release Needs evaluation
mozjs52 Not in release Not in release Not in release Ignored Ignored
mozjs68 Not in release Not in release Not in release Ignored —
mozjs78 Not in release Not in release Ignored Not in release —
mozjs91 Not in release Not in release Ignored Not in release —
thunderbird Not affected Not affected Fixed Not in release —
Show all 9 packages Show less packages

CVE-2024-10467

Medium priority

Some fixes available 2 of 13

Memory safety bugs present in Firefox 131, Firefox ESR 128.3, and Thunderbird 128.3. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run...

9 affected packages

firefox, mozjs102, mozjs115, mozjs38, mozjs52...

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox Not affected Not affected Not affected Fixed —
mozjs102 Not in release Ignored Ignored Not in release —
mozjs115 Not in release Ignored Not in release Not in release —
mozjs38 Not in release Not in release Not in release Not in release Needs evaluation
mozjs52 Not in release Not in release Not in release Ignored Ignored
mozjs68 Not in release Not in release Not in release Ignored —
mozjs78 Not in release Not in release Ignored Not in release —
mozjs91 Not in release Not in release Ignored Not in release —
thunderbird Not affected Not affected Fixed Not in release —
Show all 9 packages Show less packages

CVE-2024-10466

Medium priority

Some fixes available 2 of 13

By sending a specially crafted push message, a remote server could have hung the parent process, causing the browser to become unresponsive. This vulnerability affects Firefox < 132, Firefox ESR < 128.4, Thunderbird < 128.4, and...

9 affected packages

firefox, mozjs102, mozjs115, mozjs38, mozjs52...

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox Not affected Not affected Not affected Fixed —
mozjs102 Not in release Ignored Ignored Not in release —
mozjs115 Not in release Ignored Not in release Not in release —
mozjs38 Not in release Not in release Not in release Not in release Needs evaluation
mozjs52 Not in release Not in release Not in release Ignored Ignored
mozjs68 Not in release Not in release Not in release Ignored —
mozjs78 Not in release Not in release Ignored Not in release —
mozjs91 Not in release Not in release Ignored Not in release —
thunderbird Not affected Not affected Fixed Not in release —
Show all 9 packages Show less packages

CVE-2024-10465

Medium priority

Some fixes available 2 of 13

A clipboard "paste" button could persist across tabs which allowed a spoofing attack. This vulnerability affects Firefox < 132, Firefox ESR < 128.4, Thunderbird < 128.4, and Thunderbird < 132.

9 affected packages

firefox, mozjs102, mozjs115, mozjs38, mozjs52...

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox Not affected Not affected Not affected Fixed —
mozjs102 Not in release Ignored Ignored Not in release —
mozjs115 Not in release Ignored Not in release Not in release —
mozjs38 Not in release Not in release Not in release Not in release Needs evaluation
mozjs52 Not in release Not in release Not in release Ignored Ignored
mozjs68 Not in release Not in release Not in release Ignored —
mozjs78 Not in release Not in release Ignored Not in release —
mozjs91 Not in release Not in release Ignored Not in release —
thunderbird Not affected Not affected Fixed Not in release —
Show all 9 packages Show less packages

CVE-2024-10464

Medium priority

Some fixes available 2 of 13

Repeated writes to history interface attributes could have been used to cause a Denial of Service condition in the browser. This was addressed by introducing rate-limiting to this API. This vulnerability affects Firefox < 132,...

9 affected packages

firefox, mozjs102, mozjs115, mozjs38, mozjs52...

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox Not affected Not affected Not affected Fixed —
mozjs102 Not in release Ignored Ignored Not in release —
mozjs115 Not in release Ignored Not in release Not in release —
mozjs38 Not in release Not in release Not in release Not in release Needs evaluation
mozjs52 Not in release Not in release Not in release Ignored Ignored
mozjs68 Not in release Not in release Not in release Ignored —
mozjs78 Not in release Not in release Ignored Not in release —
mozjs91 Not in release Not in release Ignored Not in release —
thunderbird Not affected Not affected Fixed Not in release —
Show all 9 packages Show less packages

CVE-2024-10463

Medium priority

Some fixes available 3 of 14

Video frames could have been leaked between origins in some situations. This vulnerability affects Firefox < 132, Firefox ESR < 128.4, Firefox ESR < 115.17, Thunderbird < 128.4, and Thunderbird < 132.

9 affected packages

firefox, mozjs102, mozjs115, mozjs38, mozjs52...

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox Not affected Not affected Not affected Fixed —
mozjs102 Not in release Ignored Ignored Not in release —
mozjs115 Not in release Ignored Not in release Not in release —
mozjs38 Not in release Not in release Not in release Not in release Needs evaluation
mozjs52 Not in release Not in release Not in release Ignored Ignored
mozjs68 Not in release Not in release Not in release Ignored —
mozjs78 Not in release Not in release Ignored Not in release —
mozjs91 Not in release Not in release Ignored Not in release —
thunderbird Not affected Not affected Fixed Fixed —
Show all 9 packages Show less packages

CVE-2024-10462

Medium priority

Some fixes available 2 of 13

Truncation of a long URL could have allowed origin spoofing in a permission prompt. This vulnerability affects Firefox < 132, Firefox ESR < 128.4, Thunderbird < 128.4, and Thunderbird < 132.

9 affected packages

firefox, mozjs102, mozjs115, mozjs38, mozjs52...

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox Not affected Not affected Not affected Fixed —
mozjs102 Not in release Ignored Ignored Not in release —
mozjs115 Not in release Ignored Not in release Not in release —
mozjs38 Not in release Not in release Not in release Not in release Needs evaluation
mozjs52 Not in release Not in release Not in release Ignored Ignored
mozjs68 Not in release Not in release Not in release Ignored —
mozjs78 Not in release Not in release Ignored Not in release —
mozjs91 Not in release Not in release Ignored Not in release —
thunderbird Not affected Not affected Fixed Not in release —
Show all 9 packages Show less packages