CVE-2024-29944
- EPSS 1.41%
- Published 22.03.2024 13:15:07
- Last modified 01.04.2025 16:30:37
An attacker was able to inject an event handler into a privileged object that would allow arbitrary JavaScript execution in the parent process. Note: This vulnerability affects Desktop Firefox only, it does not affect mobile versions of Firefox. This...
CVE-2024-26642
- EPSS 0.01%
- Published 21.03.2024 11:15:28
- Last modified 13.03.2025 21:20:08
In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: disallow anonymous set with timeout flag Anonymous sets are never used with timeout from userspace, reject this. Exception to this rule is NFT_SET_EVAL to ens...
CVE-2024-26643
- EPSS 0.01%
- Published 21.03.2024 11:15:28
- Last modified 13.03.2025 21:20:19
In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: mark set as dead when unbinding anonymous set with timeout While the rhashtable set gc runs asynchronously, a race allows it to collect elements from anonymou...
CVE-2024-2611
- EPSS 0.2%
- Published 19.03.2024 12:15:09
- Last modified 01.04.2025 16:26:40
A missing delay on when pointer lock was used could have allowed a malicious page to trick a user into granting permissions. This vulnerability affects Firefox < 124, Firefox ESR < 115.9, and Thunderbird < 115.9.
CVE-2024-2614
- EPSS 1.33%
- Published 19.03.2024 12:15:09
- Last modified 25.02.2025 14:47:29
Memory safety bugs present in Firefox 123, Firefox ESR 115.8, and Thunderbird 115.8. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vu...
CVE-2024-2607
- EPSS 1.45%
- Published 19.03.2024 12:15:08
- Last modified 01.04.2025 17:15:20
Return registers were overwritten which could have allowed an attacker to execute arbitrary code. *Note:* This issue only affected Armv7-A systems. Other operating systems are unaffected. This vulnerability affects Firefox < 124, Firefox ESR < 115.9,...
CVE-2024-2608
- EPSS 0.16%
- Published 19.03.2024 12:15:08
- Last modified 01.04.2025 17:18:20
`AppendEncodedAttributeValue(), ExtraSpaceNeededForAttrEncoding()` and `AppendEncodedCharacters()` could have experienced integer overflows, causing underallocation of an output buffer leading to an out of bounds write. This vulnerability affects Fir...
CVE-2024-2609
- EPSS 1.03%
- Published 19.03.2024 12:15:08
- Last modified 01.04.2025 17:19:51
The permission prompt input delay could expire while the window is not in focus. This makes it vulnerable to clickjacking by malicious websites. This vulnerability affects Firefox < 124, Firefox ESR < 115.10, and Thunderbird < 115.10.
CVE-2023-5388
- EPSS 0.17%
- Published 19.03.2024 12:15:07
- Last modified 09.06.2025 17:42:06
NSS was susceptible to a timing side-channel attack when performing RSA decryption. This attack could potentially allow an attacker to recover the private data. This vulnerability affects Firefox < 124, Firefox ESR < 115.9, and Thunderbird < 115.9.
CVE-2024-2496
- EPSS 0.03%
- Published 18.03.2024 13:15:08
- Last modified 09.04.2025 15:36:43
A NULL pointer dereference flaw was found in the udevConnectListAllInterfaces() function in libvirt. This issue can occur when detaching a host interface while at the same time collecting the list of interfaces via virConnectListAllInterfaces API. Th...