Количество 26 125
Количество 26 125
CVE-2024-6611
A nested iframe, triggering a cross-site navigation, could send SameSite=Strict or Lax cookies. This vulnerability affects Firefox < 128 and Thunderbird < 128.
CVE-2024-6610
Form validation popups could capture escape key presses. Therefore, spamming form validation messages could be used to prevent users from exiting full-screen mode. This vulnerability affects Firefox < 128 and Thunderbird < 128.
CVE-2024-6608
It was possible to move the cursor using pointerlock from an iframe. This allowed moving the cursor outside of the viewport and the Firefox window. This vulnerability affects Firefox < 128 and Thunderbird < 128.
CVE-2024-6606
Out-of-bounds read in clipboard component
CVE-2024-6604
Memory safety bugs present in Firefox 127, Firefox ESR 115.12, and Thunderbird 115.12. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 128, Firefox ESR < 115.13, Thunderbird < 115.13, and Thunderbird < 128.
CVE-2024-6603
In an out-of-memory scenario an allocation could fail but free would have been called on the pointer afterwards leading to memory corruption. This vulnerability affects Firefox < 128, Firefox ESR < 115.13, Thunderbird < 115.13, and Thunderbird < 128.
CVE-2024-6601
A race condition could lead to a cross-origin container obtaining permissions of the top-level origin. This vulnerability affects Firefox < 128, Firefox ESR < 115.13, Thunderbird < 115.13, and Thunderbird < 128.
CVE-2024-6531
Rejected reason: This was not a security issue in Bootstrap. Bootstrap’s JavaScript is not intended to sanitize unsafe or intentionally dangerous HTML. As such, the reported behavior fell outside the scope of Bootstrap’s security model, and the associated CVE has been rescinded.
CVE-2024-6505
Qemu-kvm: virtio-net: queue index out-of-bounds access in software rss
CVE-2024-6485
XSS in Bootstrap button component
CVE-2024-6484
Rejected reason: This was not a security issue in Bootstrap. Bootstrap’s JavaScript is not intended to sanitize unsafe or intentionally dangerous HTML. As such, the reported behavior fell outside the scope of Bootstrap’s security model, and the associated CVE has been rescinded.
CVE-2024-6387
RedHat Openssh: CVE-2024-6387 Remote Code Execution Due To A Race Condition In Signal Handling
CVE-2024-6345
CVE-2024-6293
Chromium: CVE-2024-6293 Use after free in Dawn
CVE-2024-6292
Chromium: CVE-2024-6292 Use after free in Dawn
CVE-2024-6291
Chromium: CVE-2024-6291 Use after free in Swiftshader
CVE-2024-6290
Chromium: CVE-2024-6290 Use after free in Dawn
CVE-2024-6257
HashiCorp go-getter Vulnerable to Code Execution On Git Update Via Git Config Manipulation
CVE-2024-6232
Regular-expression DoS when parsing TarFile headers
CVE-2024-6197
Hackerone: CVE-2024-6197 Freeing stack buffer in utf8asn1str
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2024-6611 A nested iframe, triggering a cross-site navigation, could send SameSite=Strict or Lax cookies. This vulnerability affects Firefox < 128 and Thunderbird < 128. | 1% Низкий | 6 месяцев назад | ||
CVE-2024-6610 Form validation popups could capture escape key presses. Therefore, spamming form validation messages could be used to prevent users from exiting full-screen mode. This vulnerability affects Firefox < 128 and Thunderbird < 128. | 0% Низкий | 12 месяцев назад | ||
CVE-2024-6608 It was possible to move the cursor using pointerlock from an iframe. This allowed moving the cursor outside of the viewport and the Firefox window. This vulnerability affects Firefox < 128 and Thunderbird < 128. | 0% Низкий | 12 месяцев назад | ||
CVE-2024-6606 Out-of-bounds read in clipboard component | 0% Низкий | 12 месяцев назад | ||
CVE-2024-6604 Memory safety bugs present in Firefox 127, Firefox ESR 115.12, and Thunderbird 115.12. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 128, Firefox ESR < 115.13, Thunderbird < 115.13, and Thunderbird < 128. | 1% Низкий | 12 месяцев назад | ||
CVE-2024-6603 In an out-of-memory scenario an allocation could fail but free would have been called on the pointer afterwards leading to memory corruption. This vulnerability affects Firefox < 128, Firefox ESR < 115.13, Thunderbird < 115.13, and Thunderbird < 128. | 1% Низкий | 12 месяцев назад | ||
CVE-2024-6601 A race condition could lead to a cross-origin container obtaining permissions of the top-level origin. This vulnerability affects Firefox < 128, Firefox ESR < 115.13, Thunderbird < 115.13, and Thunderbird < 128. | 0% Низкий | 12 месяцев назад | ||
CVE-2024-6531 Rejected reason: This was not a security issue in Bootstrap. Bootstrap’s JavaScript is not intended to sanitize unsafe or intentionally dangerous HTML. As such, the reported behavior fell outside the scope of Bootstrap’s security model, and the associated CVE has been rescinded. | 8 месяцев назад | |||
CVE-2024-6505 Qemu-kvm: virtio-net: queue index out-of-bounds access in software rss | CVSS3: 6.8 | 1% Низкий | больше 1 года назад | |
CVE-2024-6485 XSS in Bootstrap button component | CVSS3: 6.4 | 0% Низкий | 9 месяцев назад | |
CVE-2024-6484 Rejected reason: This was not a security issue in Bootstrap. Bootstrap’s JavaScript is not intended to sanitize unsafe or intentionally dangerous HTML. As such, the reported behavior fell outside the scope of Bootstrap’s security model, and the associated CVE has been rescinded. | CVSS3: 3.9 | 7 дней назад | ||
CVE-2024-6387 RedHat Openssh: CVE-2024-6387 Remote Code Execution Due To A Race Condition In Signal Handling | CVSS3: 8.1 | 100% Критический | около 2 лет назад | |
CVSS3: 8.8 | 2% Низкий | почти 2 года назад | ||
CVE-2024-6293 Chromium: CVE-2024-6293 Use after free in Dawn | 1% Низкий | около 2 лет назад | ||
CVE-2024-6292 Chromium: CVE-2024-6292 Use after free in Dawn | 1% Низкий | около 2 лет назад | ||
CVE-2024-6291 Chromium: CVE-2024-6291 Use after free in Swiftshader | 1% Низкий | около 2 лет назад | ||
CVE-2024-6290 Chromium: CVE-2024-6290 Use after free in Dawn | 1% Низкий | около 2 лет назад | ||
CVE-2024-6257 HashiCorp go-getter Vulnerable to Code Execution On Git Update Via Git Config Manipulation | CVSS3: 8.4 | 1% Низкий | около 2 лет назад | |
CVE-2024-6232 Regular-expression DoS when parsing TarFile headers | CVSS3: 7.5 | 2% Низкий | почти 2 года назад | |
CVE-2024-6197 Hackerone: CVE-2024-6197 Freeing stack buffer in utf8asn1str | CVSS3: 8.8 | 4% Низкий | почти 2 года назад |
Уязвимостей на страницу