Search CVE reports
481 – 490 of 720 results
Some fixes available 11 of 20
When reusing existing popups Firefox would have allowed them to cover the fullscreen notification UI, which could have enabled browser spoofing attacks. This vulnerability affects Thunderbird < 91.9, Firefox ESR < 91.9, and Firefox < 100.
7 affected packages
firefox, mozjs38, mozjs52, mozjs68, mozjs78...
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
firefox | Not affected | Not affected | Fixed | Fixed |
mozjs38 | Not in release | Not in release | Not in release | Ignored |
mozjs52 | Not in release | Not in release | Ignored | Ignored |
mozjs68 | Not in release | Not in release | Ignored | Not in release |
mozjs78 | Not in release | Ignored | Not in release | Not in release |
mozjs91 | Not in release | Ignored | Not in release | Not in release |
thunderbird | Fixed | Fixed | Fixed | Fixed |
Some fixes available 11 of 20
Requests initiated through reader mode did not properly omit cookies with a SameSite attribute. This vulnerability affects Thunderbird < 91.9, Firefox ESR < 91.9, and Firefox < 100.
7 affected packages
firefox, mozjs38, mozjs52, mozjs68, mozjs91...
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
firefox | Not affected | Not affected | Fixed | Fixed |
mozjs38 | Not in release | Not in release | Not in release | Ignored |
mozjs52 | Not in release | Not in release | Ignored | Ignored |
mozjs68 | Not in release | Not in release | Ignored | Not in release |
mozjs91 | Not in release | Ignored | Not in release | Not in release |
thunderbird | Fixed | Fixed | Fixed | Fixed |
mozjs78 | Not in release | Ignored | Not in release | Not in release |
Some fixes available 11 of 20
An improper implementation of the new iframe sandbox keyword <code>allow-top-navigation-by-user-activation</code> could lead to script execution without <code>allow-scripts</code> being present. This vulnerability affects...
7 affected packages
mozjs78, firefox, mozjs38, mozjs52, mozjs68...
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
mozjs78 | Not in release | Ignored | Not in release | Not in release |
firefox | Not affected | Not affected | Fixed | Fixed |
mozjs38 | Not in release | Not in release | Not in release | Ignored |
mozjs52 | Not in release | Not in release | Ignored | Ignored |
mozjs68 | Not in release | Not in release | Ignored | Not in release |
mozjs91 | Not in release | Ignored | Not in release | Not in release |
thunderbird | Fixed | Fixed | Fixed | Fixed |
Some fixes available 11 of 20
Documents in deeply-nested cross-origin browsing contexts could have obtained permissions granted to the top-level origin, bypassing the existing prompt and wrongfully inheriting the top-level permissions. This vulnerability...
7 affected packages
mozjs78, thunderbird, mozjs91, firefox, mozjs38...
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
mozjs78 | Not in release | Ignored | Not in release | Not in release |
thunderbird | Fixed | Fixed | Fixed | Fixed |
mozjs91 | Not in release | Ignored | Not in release | Not in release |
firefox | Not affected | Not affected | Fixed | Fixed |
mozjs38 | Not in release | Not in release | Not in release | Ignored |
mozjs52 | Not in release | Not in release | Ignored | Ignored |
mozjs68 | Not in release | Not in release | Ignored | Not in release |
Some fixes available 8 of 17
Mozilla developers and community members Randell Jesup, Sebastian Hengst, and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 98. Some of these bugs showed evidence of memory corruption and we presume that...
6 affected packages
mozjs78, mozjs91, firefox, mozjs38, mozjs52, mozjs68
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
mozjs78 | Not in release | Ignored | Not in release | Not in release |
mozjs91 | Not in release | Ignored | Not in release | Not in release |
firefox | Fixed | Fixed | Fixed | Fixed |
mozjs38 | Not in release | Not in release | Not in release | Ignored |
mozjs52 | Not in release | Not in release | Ignored | Ignored |
mozjs68 | Not in release | Not in release | Ignored | Not in release |
Some fixes available 11 of 20
Mozilla developers and community members Nika Layzell, Andrew McCreight, Gabriele Svelto, and the Mozilla Fuzzing Team reported memory safety bugs present in Thunderbird 91.7. Some of these bugs showed evidence of...
7 affected packages
firefox, mozjs78, mozjs38, mozjs52, mozjs68...
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
firefox | Fixed | Fixed | Fixed | Fixed |
mozjs78 | Not in release | Ignored | Not in release | Not in release |
mozjs38 | Not in release | Not in release | Not in release | Ignored |
mozjs52 | Not in release | Not in release | Ignored | Ignored |
mozjs68 | Not in release | Not in release | Ignored | Not in release |
mozjs91 | Not in release | Ignored | Not in release | Not in release |
thunderbird | Not affected | Not affected | Fixed | Fixed |
Some fixes available 12 of 20
When generating the assembly code for <code>MLoadTypedArrayElementHole</code>, an incorrect AliasSet was used. In conjunction with another vulnerability this could have been used for an out of bounds memory read. This...
7 affected packages
firefox, mozjs78, mozjs38, mozjs52, mozjs68...
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
firefox | Fixed | Fixed | Fixed | Fixed |
mozjs78 | Not in release | Ignored | Not in release | Not in release |
mozjs38 | Not in release | Not in release | Not in release | Ignored |
mozjs52 | Not in release | Not in release | Ignored | Ignored |
mozjs68 | Not in release | Not in release | Ignored | Not in release |
mozjs91 | Not in release | Fixed | Not in release | Not in release |
thunderbird | Not affected | Not affected | Fixed | Fixed |
Some fixes available 5 of 21
Wasmtime is a standalone JIT-style runtime for WebAssembly, using Cranelift. There is a use after free vulnerability in Wasmtime when both running Wasm that uses externrefs and enabling epoch interruption in Wasmtime. If you are...
7 affected packages
firefox, mozjs38, mozjs52, mozjs68, thunderbird...
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
firefox | Fixed | Fixed | Not in release | Ignored |
mozjs38 | Not in release | Not in release | Not in release | Ignored |
mozjs52 | Not in release | Not in release | Ignored | Ignored |
mozjs68 | Not in release | Not in release | Ignored | Not in release |
thunderbird | Ignored | Ignored | Not in release | Ignored |
mozjs78 | Not in release | Ignored | Not in release | Not in release |
mozjs91 | Not in release | Ignored | Not in release | Not in release |
Some fixes available 16 of 24
When installing an add-on, Firefox verified the signature before prompting the user; but while the user was confirming the prompt, the underlying add-on file could have been modified and Firefox would not have noticed. This...
7 affected packages
mozjs78, firefox, firefox-esr, mozjs38, mozjs52...
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
mozjs78 | Not in release | Ignored | Not in release | Not in release |
firefox | Fixed | Fixed | Fixed | Fixed |
firefox-esr | — | — | — | — |
mozjs38 | Not in release | Not in release | Not in release | Ignored |
mozjs52 | Not in release | Not in release | Ignored | Ignored |
mozjs68 | Not in release | Not in release | Ignored | Not in release |
thunderbird | Fixed | Fixed | Fixed | Fixed |
Some fixes available 16 of 24
If an attacker could control the contents of an iframe sandboxed with <code>allow-popups</code> but not <code>allow-scripts</code>, they were able to craft a link that, when clicked, would lead to JavaScript execution in violation...
7 affected packages
mozjs78, firefox, firefox-esr, mozjs38, mozjs52...
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
mozjs78 | Not in release | Ignored | Not in release | Not in release |
firefox | Fixed | Fixed | Fixed | Fixed |
firefox-esr | — | — | — | — |
mozjs38 | Not in release | Not in release | Not in release | Ignored |
mozjs52 | Not in release | Not in release | Ignored | Ignored |
mozjs68 | Not in release | Not in release | Ignored | Not in release |
thunderbird | Fixed | Fixed | Fixed | Fixed |