CVE-2024-5692
- EPSS 0.41%
- Veröffentlicht 11.06.2024 13:15:50
- Zuletzt bearbeitet 27.03.2025 20:07:17
On Windows 10, when using the 'Save As' functionality, an attacker could have tricked the browser into saving the file with a disallowed extension such as `.url` by including an invalid character in the extension. *Note:* This issue only affected Win...
CVE-2024-5693
- EPSS 1.47%
- Veröffentlicht 11.06.2024 13:15:50
- Zuletzt bearbeitet 27.03.2025 20:02:24
Offscreen Canvas did not properly track cross-origin tainting, which could be used to access image data from another site in violation of same-origin policy. This vulnerability affects Firefox < 127, Firefox ESR < 115.12, and Thunderbird < 115.12.
CVE-2024-4768
- EPSS 0.71%
- Veröffentlicht 14.05.2024 18:15:14
- Zuletzt bearbeitet 01.04.2025 18:00:09
A bug in popup notifications' interaction with WebAuthn made it easier for an attacker to trick a user into granting permissions. This vulnerability affects Firefox < 126, Firefox ESR < 115.11, and Thunderbird < 115.11.
CVE-2024-4769
- EPSS 0.69%
- Veröffentlicht 14.05.2024 18:15:14
- Zuletzt bearbeitet 01.04.2025 17:46:33
When importing resources using Web Workers, error messages would distinguish the difference between `application/javascript` responses and non-script responses. This could have been abused to learn information cross-origin. This vulnerability affect...
CVE-2024-4770
- EPSS 0.46%
- Veröffentlicht 14.05.2024 18:15:14
- Zuletzt bearbeitet 01.04.2025 17:46:09
When saving a page to PDF, certain font styles could have led to a potential use-after-free crash. This vulnerability affects Firefox < 126, Firefox ESR < 115.11, and Thunderbird < 115.11.
CVE-2024-4767
- EPSS 0.87%
- Veröffentlicht 14.05.2024 18:15:13
- Zuletzt bearbeitet 01.04.2025 17:47:50
If the `browser.privatebrowsing.autostart` preference is enabled, IndexedDB files were not properly deleted when the window was closed. This preference is disabled by default in Firefox. This vulnerability affects Firefox < 126, Firefox ESR < 115.11,...
CVE-2024-3302
- EPSS 0.1%
- Veröffentlicht 16.04.2024 16:15:08
- Zuletzt bearbeitet 01.04.2025 13:39:33
There was no limit to the number of HTTP/2 CONTINUATION frames that would be processed. A server could abuse this to create an Out of Memory condition in the browser. This vulnerability affects Firefox < 125, Firefox ESR < 115.10, and Thunderbird < 1...
CVE-2024-3852
- EPSS 1.13%
- Veröffentlicht 16.04.2024 16:15:08
- Zuletzt bearbeitet 01.04.2025 13:39:19
GetBoundName could return the wrong version of an object when JIT optimizations were applied. This vulnerability affects Firefox < 125, Firefox ESR < 115.10, and Thunderbird < 115.10.
CVE-2024-3854
- EPSS 1.01%
- Veröffentlicht 16.04.2024 16:15:08
- Zuletzt bearbeitet 01.04.2025 14:11:53
In some code patterns the JIT incorrectly optimized switch statements and generated code with out-of-bounds-reads. This vulnerability affects Firefox < 125, Firefox ESR < 115.10, and Thunderbird < 115.10.
CVE-2024-3857
- EPSS 0.14%
- Veröffentlicht 16.04.2024 16:15:08
- Zuletzt bearbeitet 01.04.2025 14:16:11
The JIT created incorrect code for arguments in certain cases. This led to potential use-after-free crashes during garbage collection. This vulnerability affects Firefox < 125, Firefox ESR < 115.10, and Thunderbird < 115.10.