Логотип exploitDog
source:"msrc"
Консоль
Логотип exploitDog

exploitDog

source:"msrc"

Количество 18 047

Количество 18 047

msrc логотип

CVE-2024-6778

больше 1 года назад

Chromium: CVE-2024-6778 Race in DevTools

EPSS: Средний
msrc логотип

CVE-2024-6777

больше 1 года назад

Chromium: CVE-2024-6777 Use after free in Navigation

EPSS: Низкий
msrc логотип

CVE-2024-6776

больше 1 года назад

Chromium: CVE-2024-6776 Use after free in Audio

EPSS: Низкий
msrc логотип

CVE-2024-6775

больше 1 года назад

Chromium: CVE-2024-6775 Use after free in Media Stream

EPSS: Низкий
msrc логотип

CVE-2024-6774

больше 1 года назад

Chromium: CVE-2024-6774 Use after free in Screen Capture

EPSS: Низкий
msrc логотип

CVE-2024-6773

больше 1 года назад

Chromium: CVE-2024-6773 Type Confusion in V8

EPSS: Низкий
msrc логотип

CVE-2024-6772

больше 1 года назад

Chromium: CVE-2024-6772 Inappropriate implementation in V8

EPSS: Низкий
msrc логотип

CVE-2024-6655

больше 1 года назад

CVSS3: 7
EPSS: Низкий
msrc логотип

CVE-2024-6615

3 месяца назад

Memory safety bugs present in Firefox 127 and Thunderbird 127. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 128 and Thunderbird < 128.

EPSS: Низкий
msrc логотип

CVE-2024-6614

3 месяца назад

The frame iterator could get stuck in a loop when encountering certain wasm frames leading to incorrect stack traces. This vulnerability affects Firefox < 128 and Thunderbird < 128.

EPSS: Низкий
msrc логотип

CVE-2024-6612

3 месяца назад

CSP violations generated links in the console tab of the developer tools, pointing to the violating resource. This caused a DNS prefetch which leaked that a CSP violation happened. This vulnerability affects Firefox < 128 and Thunderbird < 128.

EPSS: Низкий
msrc логотип

CVE-2024-6611

3 месяца назад

A nested iframe, triggering a cross-site navigation, could send SameSite=Strict or Lax cookies. This vulnerability affects Firefox < 128 and Thunderbird < 128.

EPSS: Низкий
msrc логотип

CVE-2024-6610

3 месяца назад

Form validation popups could capture escape key presses. Therefore, spamming form validation messages could be used to prevent users from exiting full-screen mode. This vulnerability affects Firefox < 128 and Thunderbird < 128.

EPSS: Низкий
msrc логотип

CVE-2024-6608

3 месяца назад

It was possible to move the cursor using pointerlock from an iframe. This allowed moving the cursor outside of the viewport and the Firefox window. This vulnerability affects Firefox < 128 and Thunderbird < 128.

EPSS: Низкий
msrc логотип

CVE-2024-6604

3 месяца назад

Memory safety bugs present in Firefox 127, Firefox ESR 115.12, and Thunderbird 115.12. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 128, Firefox ESR < 115.13, Thunderbird < 115.13, and Thunderbird < 128.

EPSS: Низкий
msrc логотип

CVE-2024-6603

3 месяца назад

In an out-of-memory scenario an allocation could fail but free would have been called on the pointer afterwards leading to memory corruption. This vulnerability affects Firefox < 128, Firefox ESR < 115.13, Thunderbird < 115.13, and Thunderbird < 128.

EPSS: Низкий
msrc логотип

CVE-2024-6601

3 месяца назад

A race condition could lead to a cross-origin container obtaining permissions of the top-level origin. This vulnerability affects Firefox < 128, Firefox ESR < 115.13, Thunderbird < 115.13, and Thunderbird < 128.

EPSS: Низкий
msrc логотип

CVE-2024-6531

3 месяца назад

Rejected reason: This was not a security issue in Bootstrap. Bootstrap’s JavaScript is not intended to sanitize unsafe or intentionally dangerous HTML. As such, the reported behavior fell outside the scope of Bootstrap’s security model, and the associated CVE has been rescinded.

EPSS: Низкий
msrc логотип

CVE-2024-6505

7 месяцев назад

CVSS3: 6.8
EPSS: Низкий
msrc логотип

CVE-2024-6484

около 2 месяцев назад

Rejected reason: This was not a security issue in Bootstrap. Bootstrap’s JavaScript is not intended to sanitize unsafe or intentionally dangerous HTML. As such, the reported behavior fell outside the scope of Bootstrap’s security model, and the associated CVE has been rescinded.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
msrc логотип
CVE-2024-6778

Chromium: CVE-2024-6778 Race in DevTools

26%
Средний
больше 1 года назад
msrc логотип
CVE-2024-6777

Chromium: CVE-2024-6777 Use after free in Navigation

0%
Низкий
больше 1 года назад
msrc логотип
CVE-2024-6776

Chromium: CVE-2024-6776 Use after free in Audio

0%
Низкий
больше 1 года назад
msrc логотип
CVE-2024-6775

Chromium: CVE-2024-6775 Use after free in Media Stream

0%
Низкий
больше 1 года назад
msrc логотип
CVE-2024-6774

Chromium: CVE-2024-6774 Use after free in Screen Capture

0%
Низкий
больше 1 года назад
msrc логотип
CVE-2024-6773

Chromium: CVE-2024-6773 Type Confusion in V8

0%
Низкий
больше 1 года назад
msrc логотип
CVE-2024-6772

Chromium: CVE-2024-6772 Inappropriate implementation in V8

0%
Низкий
больше 1 года назад
msrc логотип
CVSS3: 7
0%
Низкий
больше 1 года назад
msrc логотип
CVE-2024-6615

Memory safety bugs present in Firefox 127 and Thunderbird 127. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 128 and Thunderbird < 128.

0%
Низкий
3 месяца назад
msrc логотип
CVE-2024-6614

The frame iterator could get stuck in a loop when encountering certain wasm frames leading to incorrect stack traces. This vulnerability affects Firefox < 128 and Thunderbird < 128.

0%
Низкий
3 месяца назад
msrc логотип
CVE-2024-6612

CSP violations generated links in the console tab of the developer tools, pointing to the violating resource. This caused a DNS prefetch which leaked that a CSP violation happened. This vulnerability affects Firefox < 128 and Thunderbird < 128.

0%
Низкий
3 месяца назад
msrc логотип
CVE-2024-6611

A nested iframe, triggering a cross-site navigation, could send SameSite=Strict or Lax cookies. This vulnerability affects Firefox < 128 and Thunderbird < 128.

1%
Низкий
3 месяца назад
msrc логотип
CVE-2024-6610

Form validation popups could capture escape key presses. Therefore, spamming form validation messages could be used to prevent users from exiting full-screen mode. This vulnerability affects Firefox < 128 and Thunderbird < 128.

0%
Низкий
3 месяца назад
msrc логотип
CVE-2024-6608

It was possible to move the cursor using pointerlock from an iframe. This allowed moving the cursor outside of the viewport and the Firefox window. This vulnerability affects Firefox < 128 and Thunderbird < 128.

0%
Низкий
3 месяца назад
msrc логотип
CVE-2024-6604

Memory safety bugs present in Firefox 127, Firefox ESR 115.12, and Thunderbird 115.12. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 128, Firefox ESR < 115.13, Thunderbird < 115.13, and Thunderbird < 128.

1%
Низкий
3 месяца назад
msrc логотип
CVE-2024-6603

In an out-of-memory scenario an allocation could fail but free would have been called on the pointer afterwards leading to memory corruption. This vulnerability affects Firefox < 128, Firefox ESR < 115.13, Thunderbird < 115.13, and Thunderbird < 128.

0%
Низкий
3 месяца назад
msrc логотип
CVE-2024-6601

A race condition could lead to a cross-origin container obtaining permissions of the top-level origin. This vulnerability affects Firefox < 128, Firefox ESR < 115.13, Thunderbird < 115.13, and Thunderbird < 128.

0%
Низкий
3 месяца назад
msrc логотип
CVE-2024-6531

Rejected reason: This was not a security issue in Bootstrap. Bootstrap’s JavaScript is not intended to sanitize unsafe or intentionally dangerous HTML. As such, the reported behavior fell outside the scope of Bootstrap’s security model, and the associated CVE has been rescinded.

3 месяца назад
msrc логотип
CVSS3: 6.8
0%
Низкий
7 месяцев назад
msrc логотип
CVE-2024-6484

Rejected reason: This was not a security issue in Bootstrap. Bootstrap’s JavaScript is not intended to sanitize unsafe or intentionally dangerous HTML. As such, the reported behavior fell outside the scope of Bootstrap’s security model, and the associated CVE has been rescinded.

около 2 месяцев назад

Уязвимостей на страницу