CVE-2024-11700
- EPSS 0.13%
- Veröffentlicht 26.11.2024 14:15:19
- Zuletzt bearbeitet 03.04.2025 13:32:01
Malicious websites may have been able to perform user intent confirmation through tapjacking. This could have led to users unknowingly approving the launch of external applications, potentially exposing them to underlying vulnerabilities. This vulner...
CVE-2024-11701
- EPSS 0.11%
- Veröffentlicht 26.11.2024 14:15:19
- Zuletzt bearbeitet 05.04.2025 00:36:49
The incorrect domain may have been displayed in the address bar during an interrupted navigation attempt. This could have led to user confusion and possible spoofing attacks. This vulnerability affects Firefox < 133 and Thunderbird < 133.
CVE-2024-11702
- EPSS 0.21%
- Veröffentlicht 26.11.2024 14:15:19
- Zuletzt bearbeitet 05.04.2025 00:41:30
Copying sensitive information from Private Browsing tabs on Android, such as passwords, may have inadvertently stored data in the cloud-based clipboard history if enabled. This vulnerability affects Firefox < 133 and Thunderbird < 133.
CVE-2024-11704
- EPSS 0.62%
- Veröffentlicht 26.11.2024 14:15:19
- Zuletzt bearbeitet 07.04.2025 19:40:06
A double-free issue could have occurred in `sec_pkcs7_decoder_start_decrypt()` when handling an error path. Under specific conditions, the same symmetric key could have been freed twice, potentially leading to memory corruption. This vulnerability af...
CVE-2024-11705
- EPSS 0.49%
- Veröffentlicht 26.11.2024 14:15:19
- Zuletzt bearbeitet 24.06.2025 17:07:46
`NSC_DeriveKey` inadvertently assumed that the `phKey` parameter is always non-NULL. When it was passed as NULL, a segmentation fault (SEGV) occurred, leading to crashes. This behavior conflicted with the PKCS#11 v3.0 specification, which allows `phK...
CVE-2024-11691
- EPSS 0.5%
- Veröffentlicht 26.11.2024 14:15:18
- Zuletzt bearbeitet 06.01.2025 18:15:18
Certain WebGL operations on Apple silicon M series devices could have lead to an out-of-bounds write and memory corruption due to a flaw in Apple's GPU driver. *This bug only affected the application on Apple M series hardware. Other platforms were...
CVE-2024-11692
- EPSS 0.2%
- Veröffentlicht 26.11.2024 14:15:18
- Zuletzt bearbeitet 03.04.2025 13:31:37
An attacker could cause a select dropdown to be shown over another tab; this could have led to user confusion and possible spoofing attacks. This vulnerability affects Firefox < 133, Firefox ESR < 128.5, Thunderbird < 133, and Thunderbird < 128.5.
CVE-2024-11693
- EPSS 0.63%
- Veröffentlicht 26.11.2024 14:15:18
- Zuletzt bearbeitet 03.04.2025 13:31:28
The executable file warning was not presented when downloading .library-ms files. *Note: This issue only affected Windows operating systems. Other operating systems are unaffected.* This vulnerability affects Firefox < 133, Firefox ESR < 128.5, Thu...
CVE-2024-11694
- EPSS 0.41%
- Veröffentlicht 26.11.2024 14:15:18
- Zuletzt bearbeitet 13.12.2024 17:15:05
Enhanced Tracking Protection's Strict mode may have inadvertently allowed a CSP `frame-src` bypass and DOM-based XSS through the Google SafeFrame shim in the Web Compatibility extension. This issue could have exposed users to malicious frames masquer...
CVE-2024-11159
- EPSS 0.08%
- Veröffentlicht 13.11.2024 14:15:15
- Zuletzt bearbeitet 06.12.2024 20:15:23
Using remote content in OpenPGP encrypted messages can lead to the disclosure of plaintext. This vulnerability affects Thunderbird < 128.4.3 and Thunderbird < 132.0.1.