Search CVE reports


Toggle filters

851 – 860 of 997 results


CVE-2023-4055

Medium priority

Some fixes available 5 of 16

When the number of cookies per domain was exceeded in `document.cookie`, the actual cookie jar sent to the host was no longer consistent with expected cookie jar state. This could have caused requests to be sent with some cookies...

8 affected packages

firefox, mozjs102, mozjs38, mozjs52, mozjs68...

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox — Not affected Not affected Not in release Ignored
mozjs102 — Ignored Ignored Not in release Not in release
mozjs38 — Not in release Not in release Not in release Ignored
mozjs52 — Not in release Not in release Ignored Ignored
mozjs68 — Not in release Not in release Ignored Not in release
mozjs78 — Not in release Ignored Not in release Not in release
mozjs91 — Not in release Ignored Not in release Not in release
thunderbird — Fixed Fixed Fixed Ignored
Show all 8 packages Show less packages

CVE-2023-4054

Medium priority

Some fixes available 4 of 16

When opening appref-ms files, Firefox did not warn the user that these files may contain malicious code. *This bug only affects Firefox on Windows. Other operating systems are unaffected.* This vulnerability affects Firefox < 116,...

8 affected packages

firefox, mozjs102, mozjs38, mozjs52, mozjs68...

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox — Not affected Not affected Not in release Ignored
mozjs102 — Ignored Ignored Not in release Not in release
mozjs38 — Not in release Not in release Not in release Ignored
mozjs52 — Not in release Not in release Ignored Ignored
mozjs68 — Not in release Not in release Ignored Not in release
mozjs78 — Not in release Ignored Not in release Not in release
mozjs91 — Not in release Ignored Not in release Not in release
thunderbird — Fixed Fixed Fixed Ignored
Show all 8 packages Show less packages

CVE-2023-4053

Medium priority

Some fixes available 1 of 12

A website could have obscured the full screen notification by using a URL with a scheme handled by an external program, such as a mailto URL. This could have led to user confusion and possible spoofing attacks. This vulnerability...

8 affected packages

firefox, mozjs102, mozjs38, mozjs52, mozjs68...

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox — Not affected Not affected Fixed Ignored
mozjs102 — Ignored Ignored Not in release Not in release
mozjs38 — Not in release Not in release Not in release Ignored
mozjs52 — Not in release Not in release Ignored Ignored
mozjs68 — Not in release Not in release Ignored Not in release
mozjs78 — Not in release Ignored Not in release Not in release
mozjs91 — Not in release Ignored Not in release Not in release
thunderbird — Not affected Not affected Not in release Ignored
Show all 8 packages Show less packages

CVE-2023-4052

Medium priority
Ignored

The Firefox updater created a directory writable by non-privileged users. When uninstalling Firefox, any files in that directory would be recursively deleted with the permissions of the uninstalling user account. This could be...

8 affected packages

firefox, mozjs102, mozjs38, mozjs52, mozjs68...

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox — Not affected Not affected Not in release Ignored
mozjs102 — Ignored Ignored Not in release Not in release
mozjs38 — Not in release Not in release Not in release Ignored
mozjs52 — Not in release Not in release Ignored Ignored
mozjs68 — Not in release Not in release Ignored Not in release
mozjs78 — Not in release Ignored Not in release Not in release
mozjs91 — Not in release Ignored Not in release Not in release
thunderbird — Not affected Not affected Not in release Ignored
Show all 8 packages Show less packages

CVE-2023-4051

Medium priority

Some fixes available 1 of 12

A website could have obscured the full screen notification by using the file open dialog. This could have led to user confusion and possible spoofing attacks. This vulnerability affects Firefox < 116, Firefox ESR < 115.2, and...

8 affected packages

firefox, mozjs102, mozjs38, mozjs52, mozjs68...

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox — Not affected Not affected Fixed Ignored
mozjs102 — Ignored Ignored Not in release Not in release
mozjs38 — Not in release Not in release Not in release Ignored
mozjs52 — Not in release Not in release Ignored Ignored
mozjs68 — Not in release Not in release Ignored Not in release
mozjs78 — Not in release Ignored Not in release Not in release
mozjs91 — Not in release Ignored Not in release Not in release
thunderbird — Not affected Not affected Not in release Ignored
Show all 8 packages Show less packages

CVE-2023-4050

Medium priority

Some fixes available 6 of 17

In some cases, an untrusted input stream was copied to a stack buffer without checking its size. This resulted in a potentially exploitable crash which could have led to a sandbox escape. This vulnerability affects Firefox < 116,...

8 affected packages

firefox, mozjs102, mozjs38, mozjs52, mozjs68...

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox — Not affected Not affected Fixed Ignored
mozjs102 — Ignored Ignored Not in release Not in release
mozjs38 — Not in release Not in release Not in release Ignored
mozjs52 — Not in release Not in release Ignored Ignored
mozjs68 — Not in release Not in release Ignored Not in release
mozjs78 — Not in release Ignored Not in release Not in release
mozjs91 — Not in release Ignored Not in release Not in release
thunderbird — Fixed Fixed Fixed Ignored
Show all 8 packages Show less packages

CVE-2023-4049

Medium priority

Some fixes available 6 of 17

Race conditions in reference counting code were found through code inspection. These could have resulted in potentially exploitable use-after-free vulnerabilities. This vulnerability affects Firefox < 116, Firefox ESR < 102.14,...

8 affected packages

firefox, mozjs102, mozjs38, mozjs52, mozjs68...

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox — Not affected Not affected Fixed Ignored
mozjs102 — Ignored Ignored Not in release Not in release
mozjs38 — Not in release Not in release Not in release Ignored
mozjs52 — Not in release Not in release Ignored Ignored
mozjs68 — Not in release Not in release Ignored Not in release
mozjs78 — Not in release Ignored Not in release Not in release
mozjs91 — Not in release Ignored Not in release Not in release
thunderbird — Fixed Fixed Fixed Ignored
Show all 8 packages Show less packages

CVE-2023-4048

Medium priority

Some fixes available 6 of 17

An out-of-bounds read could have led to an exploitable crash when parsing HTML with DOMParser in low memory situations. This vulnerability affects Firefox < 116, Firefox ESR < 102.14, and Firefox ESR < 115.1.

8 affected packages

firefox, mozjs102, mozjs38, mozjs52, mozjs68...

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox — Not affected Not affected Fixed Ignored
mozjs102 — Ignored Ignored Not in release Not in release
mozjs38 — Not in release Not in release Not in release Ignored
mozjs52 — Not in release Not in release Ignored Ignored
mozjs68 — Not in release Not in release Ignored Not in release
mozjs78 — Not in release Ignored Not in release Not in release
mozjs91 — Not in release Ignored Not in release Not in release
thunderbird — Fixed Fixed Fixed Ignored
Show all 8 packages Show less packages

CVE-2023-4047

Medium priority

Some fixes available 6 of 17

A bug in popup notifications delay calculation could have made it possible for an attacker to trick a user into granting permissions. This vulnerability affects Firefox < 116, Firefox ESR < 102.14, and Firefox ESR < 115.1.

8 affected packages

firefox, mozjs102, mozjs38, mozjs52, mozjs68...

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox — Not affected Not affected Fixed Ignored
mozjs102 — Ignored Ignored Not in release Not in release
mozjs38 — Not in release Not in release Not in release Ignored
mozjs52 — Not in release Not in release Ignored Ignored
mozjs68 — Not in release Not in release Ignored Not in release
mozjs78 — Not in release Ignored Not in release Not in release
mozjs91 — Not in release Ignored Not in release Not in release
thunderbird — Fixed Fixed Fixed Ignored
Show all 8 packages Show less packages

CVE-2023-4046

Medium priority

Some fixes available 8 of 15

In some circumstances, a stale value could have been used for a global variable in WASM JIT analysis. This resulted in incorrect compilation and a potentially exploitable crash in the content process. This vulnerability affects...

8 affected packages

firefox, mozjs102, mozjs38, mozjs52, mozjs68...

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox — Not affected Not affected Fixed Ignored
mozjs102 — Not affected Fixed Not in release Not in release
mozjs38 — Not in release Not in release Not in release Ignored
mozjs52 — Not in release Not in release Ignored Ignored
mozjs68 — Not in release Not in release Ignored Not in release
mozjs78 — Not in release Ignored Not in release Not in release
mozjs91 — Not in release Ignored Not in release Not in release
thunderbird — Fixed Fixed Fixed Ignored
Show all 8 packages Show less packages