8.8

CVSS3.1

CVE-2024-7520 - mozilla: Type confusion in WebAssembly

A type confusion bug in WebAssembly could be leveraged by an attacker to potentially achieve code execution. This vulnerability affects Firefox < 129, Firefox ESR < 128.1, and Thunderbird < 128.1.

πŸ“… Published: Aug. 6, 2024, midnight πŸ”„ Last Modified: March 24, 2025, 5:15 p.m.

6.1

CVSS3.1

CVE-2023-40819 -

ID4Portais in version < V.2022.837.002a returns message parameter unsanitized in the response, resulting in a HTML Injection vulnerability.

πŸ“… Published: Aug. 6, 2024, midnight πŸ”„ Last Modified: Aug. 12, 2024, 4:12 p.m.

7.2

CVSS3.1

CVE-2024-40101 -

A Reflected Cross-site scripting (XSS) vulnerability exists in '/search' in microweber 2.0.15 and earlier allowing unauthenticated remote attackers to inject arbitrary web script or HTML via the 'keywords' parameter.

πŸ“… Published: Aug. 6, 2024, midnight πŸ”„ Last Modified: March 25, 2025, 2:15 p.m.

9.8

CVSS3.1

CVE-2024-7521 - mozilla: Incomplete WebAssembly exception handing

Incomplete WebAssembly exception handing could have led to a use-after-free. This vulnerability affects Firefox < 129, Firefox ESR < 115.14, Firefox ESR < 128.1, Thunderbird < 128.1, and Thunderbird < 115.14.

πŸ“… Published: Aug. 6, 2024, midnight πŸ”„ Last Modified: Aug. 12, 2024, 4:05 p.m.

9.1

CVSS3.1

CVE-2024-7525 - mozilla: Missing permission check when creating a StreamFilter

It was possible for a web extension with minimal permissions to create a `StreamFilter` which could be used to read and modify the response body of requests on any site. This vulnerability affects Firefox < 129, Firefox ESR < 115.14, Firefox ESR < 128.1, Thunderbird < 128.1, and Thunderbird < 115.1…

πŸ“… Published: Aug. 6, 2024, midnight πŸ”„ Last Modified: Aug. 12, 2024, 4:07 p.m.

9.1

CVSS3.1

CVE-2024-41270 -

An issue discovered in the RunHTTPServer function in Gorush v1.18.4 allows attackers to intercept and manipulate data due to use of deprecated TLS version.

πŸ“… Published: Aug. 6, 2024, midnight πŸ”„ Last Modified: Aug. 12, 2024, 6:25 p.m.

6.3

CVSS3.1

CVE-2024-42218 -

1Password 8 before 8.10.38 for macOS allows local attackers to exfiltrate vault items by bypassing macOS-specific security mechanisms.

πŸ“… Published: Aug. 6, 2024, midnight πŸ”„ Last Modified: Aug. 12, 2024, 6:27 p.m.

8.8

CVSS3.1

CVE-2024-7527 - mozilla: Use-after-free in JavaScript garbage collection

Unexpected marking work at the start of sweeping could have led to a use-after-free. This vulnerability affects Firefox < 129, Firefox ESR < 115.14, Firefox ESR < 128.1, Thunderbird < 128.1, and Thunderbird < 115.14.

πŸ“… Published: Aug. 6, 2024, midnight πŸ”„ Last Modified: March 18, 2025, 7:15 p.m.

6.1

CVSS3.1

CVE-2024-7524 - mozilla: CSP strict-dynamic bypass using web-compatibility shims

Firefox adds web-compatibility shims in place of some tracking scripts blocked by Enhanced Tracking Protection. On a site protected by Content Security Policy in "strict-dynamic" mode, an attacker able to inject an HTML element could have used a DOM Clobbering attack on some of the shims and achie…

πŸ“… Published: Aug. 6, 2024, midnight πŸ”„ Last Modified: March 25, 2025, 5:16 p.m.

8.8

CVSS3.1

CVE-2024-7519 - mozilla: Out of bounds memory access in graphics shared memory handling

Insufficient checks when processing graphics shared memory could have led to memory corruption. This could be leveraged by an attacker to perform a sandbox escape. This vulnerability affects Firefox < 129, Firefox ESR < 115.14, Firefox ESR < 128.1, Thunderbird < 128.1, and Thunderbird < 115.14.

πŸ“… Published: Aug. 6, 2024, midnight πŸ”„ Last Modified: Aug. 12, 2024, 4:04 p.m.
Total resulsts: 349182
Page 8948 of 34,919
Β« previous page Β» next page
Filters