Search CVE reports
251 – 260 of 2820 results
Some fixes available 4 of 13
A malicious website could have used a combination of exiting fullscreen mode and `requestPointerLock` to cause the user's mouse to be re-positioned unexpectedly, which could have led to user confusion and inadvertently granting...
8 affected packages
firefox, thunderbird, mozjs38, mozjs52, mozjs68...
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
firefox | Not affected | Not affected | Fixed | Ignored |
thunderbird | Not affected | Fixed | Fixed | Ignored |
mozjs38 | Not in release | Not in release | Not in release | Ignored |
mozjs52 | Not in release | Not in release | Ignored | Ignored |
mozjs68 | Not in release | Not in release | Ignored | Not in release |
mozjs78 | Not in release | Ignored | Not in release | Not in release |
mozjs91 | Not in release | Ignored | Not in release | Not in release |
mozjs102 | Ignored | Ignored | Not in release | Not in release |
Some fixes available 4 of 13
If a website set a large custom cursor, portions of the cursor could have overlapped with the permission dialog, potentially resulting in user confusion and unexpected granted permissions. This vulnerability affects Firefox < 123,...
8 affected packages
firefox, thunderbird, mozjs38, mozjs52, mozjs68...
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
firefox | Not affected | Not affected | Fixed | Ignored |
thunderbird | Not affected | Fixed | Fixed | Ignored |
mozjs38 | Not in release | Not in release | Not in release | Ignored |
mozjs52 | Not in release | Not in release | Ignored | Ignored |
mozjs68 | Not in release | Not in release | Ignored | Not in release |
mozjs78 | Not in release | Ignored | Not in release | Not in release |
mozjs91 | Not in release | Ignored | Not in release | Not in release |
mozjs102 | Ignored | Ignored | Not in release | Not in release |
Some fixes available 4 of 13
A website could have obscured the fullscreen notification by using a dropdown select input element. This could have led to user confusion and possible spoofing attacks. This vulnerability affects Firefox < 123, Firefox ESR <...
8 affected packages
firefox, thunderbird, mozjs38, mozjs52, mozjs68...
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
firefox | Not affected | Not affected | Fixed | Ignored |
thunderbird | Not affected | Fixed | Fixed | Ignored |
mozjs38 | Not in release | Not in release | Not in release | Ignored |
mozjs52 | Not in release | Not in release | Ignored | Ignored |
mozjs68 | Not in release | Not in release | Ignored | Not in release |
mozjs78 | Not in release | Ignored | Not in release | Not in release |
mozjs91 | Not in release | Ignored | Not in release | Not in release |
mozjs102 | Ignored | Ignored | Not in release | Not in release |
Some fixes available 4 of 13
Through a series of API calls and redirects, an attacker-controlled alert dialog could have been displayed on another website (with the victim website's URL shown). This vulnerability affects Firefox < 123, Firefox ESR < 115.8,...
8 affected packages
firefox, thunderbird, mozjs38, mozjs52, mozjs68...
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
firefox | Not affected | Not affected | Fixed | Ignored |
thunderbird | Not affected | Fixed | Fixed | Ignored |
mozjs38 | Not in release | Not in release | Not in release | Ignored |
mozjs52 | Not in release | Not in release | Ignored | Ignored |
mozjs68 | Not in release | Not in release | Ignored | Not in release |
mozjs78 | Not in release | Ignored | Not in release | Not in release |
mozjs91 | Not in release | Ignored | Not in release | Not in release |
mozjs102 | Ignored | Ignored | Not in release | Not in release |
Some fixes available 4 of 13
When storing and re-accessing data on a networking channel, the length of buffers may have been confused, resulting in an out-of-bounds memory read. This vulnerability affects Firefox < 123, Firefox ESR < 115.8, and Thunderbird < 115.8.
8 affected packages
firefox, thunderbird, mozjs38, mozjs52, mozjs68...
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
firefox | Not affected | Not affected | Fixed | Ignored |
thunderbird | Not affected | Fixed | Fixed | Ignored |
mozjs38 | Not in release | Not in release | Not in release | Ignored |
mozjs52 | Not in release | Not in release | Ignored | Ignored |
mozjs68 | Not in release | Not in release | Ignored | Not in release |
mozjs78 | Not in release | Ignored | Not in release | Not in release |
mozjs91 | Not in release | Ignored | Not in release | Not in release |
mozjs102 | Ignored | Ignored | Not in release | Not in release |
Some fixes available 1 of 12
Missing thread synchronization primitives could have led to a data race on members of the PlaybackParams structure. This vulnerability affects Firefox < 133 and Thunderbird < 133.
9 affected packages
firefox, thunderbird, mozjs38, mozjs52, mozjs68...
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
firefox | Not affected | Not affected | Fixed | — |
thunderbird | Not affected | Not affected | Not in release | — |
mozjs38 | Not in release | Not in release | Not in release | Needs evaluation |
mozjs52 | Not in release | Not in release | Needs evaluation | Ignored |
mozjs68 | Not in release | Not in release | Ignored | — |
mozjs78 | Not in release | Ignored | Not in release | — |
mozjs91 | Not in release | Ignored | Not in release | — |
mozjs102 | Ignored | Ignored | Not in release | — |
mozjs115 | Ignored | Not in release | Not in release | — |
Some fixes available 1 of 12
A null pointer dereference may have inadvertently occurred in `pk12util`, and specifically in the `SEC_ASN1DecodeItem_Util` function, when handling malformed or improperly formatted input files. This vulnerability affects Firefox...
9 affected packages
firefox, thunderbird, mozjs38, mozjs52, mozjs68...
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
firefox | Not affected | Not affected | Fixed | — |
thunderbird | Not affected | Not affected | Not in release | — |
mozjs38 | Not in release | Not in release | Not in release | Needs evaluation |
mozjs52 | Not in release | Not in release | Needs evaluation | Ignored |
mozjs68 | Not in release | Not in release | Ignored | — |
mozjs78 | Not in release | Ignored | Not in release | — |
mozjs91 | Not in release | Ignored | Not in release | — |
mozjs102 | Ignored | Ignored | Not in release | — |
mozjs115 | Ignored | Not in release | Not in release | — |
Some fixes available 1 of 12
`NSC_DeriveKey` inadvertently assumed that the `phKey` parameter is always non-NULL. When it was passed as NULL, a segmentation fault (SEGV) occurred, leading to crashes. This behavior conflicted with the PKCS#11...
9 affected packages
firefox, thunderbird, mozjs38, mozjs52, mozjs68...
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
firefox | Not affected | Not affected | Fixed | — |
thunderbird | Not affected | Not affected | Not in release | — |
mozjs38 | Not in release | Not in release | Not in release | Needs evaluation |
mozjs52 | Not in release | Not in release | Needs evaluation | Ignored |
mozjs68 | Not in release | Not in release | Ignored | — |
mozjs78 | Not in release | Ignored | Not in release | — |
mozjs91 | Not in release | Ignored | Not in release | — |
mozjs102 | Ignored | Ignored | Not in release | — |
mozjs115 | Ignored | Not in release | Not in release | — |
Some fixes available 1 of 12
A double-free issue could have occurred in `sec_pkcs7_decoder_start_decrypt()` when handling an error path. Under specific conditions, the same symmetric key could have been freed twice, potentially leading to memory corruption....
9 affected packages
firefox, thunderbird, mozjs38, mozjs52, mozjs68...
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
firefox | Not affected | Not affected | Fixed | — |
thunderbird | Not affected | Not affected | Not in release | — |
mozjs38 | Not in release | Not in release | Not in release | Needs evaluation |
mozjs52 | Not in release | Not in release | Needs evaluation | Ignored |
mozjs68 | Not in release | Not in release | Ignored | — |
mozjs78 | Not in release | Ignored | Not in release | — |
mozjs91 | Not in release | Ignored | Not in release | — |
mozjs102 | Ignored | Ignored | Not in release | — |
mozjs115 | Ignored | Not in release | Not in release | — |
On Android, Firefox may have inadvertently allowed viewing saved passwords without the required device PIN authentication. This vulnerability affects Firefox < 133.
9 affected packages
firefox, thunderbird, mozjs38, mozjs52, mozjs68...
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
firefox | Not affected | Not affected | Not in release | — |
thunderbird | Not affected | Not affected | Not in release | — |
mozjs38 | Not in release | Not in release | Not in release | Needs evaluation |
mozjs52 | Not in release | Not in release | Needs evaluation | Ignored |
mozjs68 | Not in release | Not in release | Ignored | — |
mozjs78 | Not in release | Ignored | Not in release | — |
mozjs91 | Not in release | Ignored | Not in release | — |
mozjs102 | Ignored | Ignored | Not in release | — |
mozjs115 | Ignored | Not in release | Not in release | — |