6.1

CVSS3.1

CVE-2024-11694 - firefox: thunderbird: CSP Bypass and XSS Exposure via Web Compatibility Shims

Enhanced Tracking Protection's Strict mode may have inadvertently allowed a CSP `frame-src` bypass and DOM-based XSS through the Google SafeFrame shim in the Web Compatibility extension. This issue could have exposed users to malicious frames masquerading as legitimate content. This vulnerability aโ€ฆ

๐Ÿ“… Published: Nov. 26, 2024, 1:33 p.m. ๐Ÿ”„ Last Modified: Nov. 3, 2025, 10:16 p.m.

9.8

CVSS3.1

CVE-2024-11693 - firefox: thunderbird: Download Protections were bypassed by .library-ms files on Windows

The executable file warning was not presented when downloading .library-ms files. *Note: This issue only affected Windows operating systems. Other operating systems are unaffected.* This vulnerability affects Firefox < 133, Firefox ESR < 128.5, Thunderbird < 133, and Thunderbird < 128.5.

๐Ÿ“… Published: Nov. 26, 2024, 1:33 p.m. ๐Ÿ”„ Last Modified: April 3, 2025, 1:31 p.m.

7.5

CVSS3.1

CVE-2024-11702 - firefox: thunderbird: Inadequate Clipboard Protection in Private Browsing Mode on Android

Copying sensitive information from Private Browsing tabs on Android, such as passwords, may have inadvertently stored data in the cloud-based clipboard history if enabled. This vulnerability affects Firefox < 133 and Thunderbird < 133.

๐Ÿ“… Published: Nov. 26, 2024, 1:33 p.m. ๐Ÿ”„ Last Modified: April 5, 2025, 12:41 a.m.

8.1

CVSS3.1

CVE-2024-11700 - firefox: thunderbird: Potential Tapjacking Exploit for Intent Confirmation on Android

Malicious websites may have been able to perform user intent confirmation through tapjacking. This could have led to users unknowingly approving the launch of external applications, potentially exposing them to underlying vulnerabilities. This vulnerability affects Firefox < 133 and Thunderbird < 1โ€ฆ

๐Ÿ“… Published: Nov. 26, 2024, 1:33 p.m. ๐Ÿ”„ Last Modified: April 3, 2025, 1:32 p.m.

4.3

CVSS3.1

CVE-2024-11701 - firefox: thunderbird: Misleading Address Bar State During Navigation Interruption

The incorrect domain may have been displayed in the address bar during an interrupted navigation attempt. This could have led to user confusion and possible spoofing attacks. This vulnerability affects Firefox < 133 and Thunderbird < 133.

๐Ÿ“… Published: Nov. 26, 2024, 1:33 p.m. ๐Ÿ”„ Last Modified: April 5, 2025, 12:36 a.m.

4.3

CVSS3.1

CVE-2024-11692 - firefox: thunderbird: Select list elements could be shown over another site

An attacker could cause a select dropdown to be shown over another tab; this could have led to user confusion and possible spoofing attacks. This vulnerability affects Firefox < 133, Firefox ESR < 128.5, Thunderbird < 133, and Thunderbird < 128.5.

๐Ÿ“… Published: Nov. 26, 2024, 1:33 p.m. ๐Ÿ”„ Last Modified: Nov. 3, 2025, 10:16 p.m.

8.8

CVSS3.1

CVE-2024-11691 - firefox: thunderbird: Memory corruption in Apple GPU drivers

Certain WebGL operations on Apple silicon M series devices could have lead to an out-of-bounds write and memory corruption due to a flaw in Apple's GPU driver. *This bug only affected the application on Apple M series hardware. Other platforms were unaffected.* This vulnerability affects Firefox โ€ฆ

๐Ÿ“… Published: Nov. 26, 2024, 1:33 p.m. ๐Ÿ”„ Last Modified: June 24, 2025, 4:58 p.m.

4.3

CVSS3.1

CVE-2024-9929 -

A vulnerability exists in NSD570 that allows any authenticated user to access all device logs disclosing login information with timestamps.

๐Ÿ“… Published: Nov. 26, 2024, 1:31 p.m. ๐Ÿ”„ Last Modified: Nov. 26, 2024, 3:20 p.m.

5.3

CVSS3.1

CVE-2024-9928 -

A vulnerability exists in NSD570 login panel that does not restrict excessive authentication attempts. If exploited, this could cause account takeover and unauthorized access to the system when an attacker conducts brute-force attacks against the equipment login. Note that the system supports only โ€ฆ

๐Ÿ“… Published: Nov. 26, 2024, 1:26 p.m. ๐Ÿ”„ Last Modified: Nov. 26, 2024, 4:11 p.m.

7.8

CVSS3.1

CVE-2024-52336 - Tuned: `script_pre` and `script_post` options allow to pass arbitrary scripts executed by root

A script injection vulnerability was identified in the Tuned package. The `instance_create()` D-Bus function can be called by locally logged-in users without authentication. This flaw allows a local non-privileged user to execute a D-Bus call with `script_pre` or `script_post` options that permit aโ€ฆ

๐Ÿ“… Published: Nov. 26, 2024, noon ๐Ÿ”„ Last Modified: Nov. 8, 2025, 3:14 a.m.
Total resulsts: 343974
Page 7176 of 34,398
ยซ previous page ยป next page
Filters