8.4
CVE-2017-18306 - Information Exposure in Camera Driver
Information disclosure due to uninitialized variable.
7.8
CVE-2016-10408 - Improper Access Control in Core.
QSEE will randomly experience a fatal error during execution due to speculative instruction fetches from device memory. Device memory is not valid executable memory.
5.4
CVE-2024-53976 -
Under certain circumstances, navigating to a webpage would result in the address missing from the location URL bar, making it unclear what the URL was for the loaded webpage. This vulnerability affects Firefox for iOS < 133.
5.4
CVE-2024-53975 -
Accessing a non-secure HTTP site that uses a non-existent port may cause the SSL padlock icon in the location URL bar to, misleadingly, appear secure. This vulnerability affects Firefox for iOS < 133.
8.8
CVE-2024-11699 - firefox: thunderbird: Memory safety bugs fixed in Firefox 133, Thunderbird 133, Firefox ESR 128.5, β¦
Memory safety bugs present in Firefox 132, Firefox ESR 128.4, and Thunderbird 128.4. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 133, Firefox ESR < β¦
6.5
CVE-2024-11708 - firefox: thunderbird: Data race with PlaybackParams
Missing thread synchronization primitives could have led to a data race on members of the PlaybackParams structure. This vulnerability affects Firefox < 133 and Thunderbird < 133.
9.1
CVE-2024-11705 - firefox: thunderbird: Null Pointer Dereference in NSC_DeriveKey
`NSC_DeriveKey` inadvertently assumed that the `phKey` parameter is always non-NULL. When it was passed as NULL, a segmentation fault (SEGV) occurred, leading to crashes. This behavior conflicted with the PKCS#11 v3.0 specification, which allows `phKey` to be NULL for certain mechanisms. This vulneβ¦
6.5
CVE-2024-11706 - firefox: thunderbird: Null Pointer Dereference in PKCS#12 Utility
A null pointer dereference may have inadvertently occurred in `pk12util`, and specifically in the `SEC_ASN1DecodeItem_Util` function, when handling malformed or improperly formatted input files. This vulnerability affects Firefox < 133 and Thunderbird < 133.
9.8
CVE-2024-11698 - firefox: thunderbird: Fullscreen Lock-Up When Modal Dialog Interrupts Transition on macOS
A flaw in handling fullscreen transitions may have inadvertently caused the application to become stuck in fullscreen mode when a modal dialog was opened during the transition. This issue left users unable to exit fullscreen mode using standard actions like pressing "Esc" or accessing right-click mβ¦
8.8
CVE-2024-11697 - firefox: thunderbird: Improper Keypress Handling in Executable File Confirmation Dialog
When handling keypress events, an attacker may have been able to trick a user into bypassing the "Open Executable File?" confirmation dialog. This could have led to malicious code execution. This vulnerability affects Firefox < 133, Firefox ESR < 128.5, Thunderbird < 133, and Thunderbird < 128.5.