Search CVE reports


Toggle filters

921 – 930 of 3497 results


CVE-2024-3863

Medium priority
Not affected

The executable file warning was not presented when downloading .xrm-ms files. *Note: This issue only affected Windows operating systems. Other operating systems are unaffected.* This vulnerability affects Firefox < 125,...

8 affected packages

firefox, mozjs102, mozjs38, mozjs52, mozjs68...

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox — Not affected Not affected Not in release —
mozjs102 — Not affected Not affected Not in release —
mozjs38 — Not in release Not in release Not in release Not affected
mozjs52 — Not in release Not in release Not affected Not affected
mozjs68 — Not in release Not in release Not affected —
mozjs78 — Not in release Not affected Not in release —
mozjs91 — Not in release Not affected Not in release —
thunderbird — Not affected Not affected Not in release —
Show all 8 packages Show less packages

CVE-2024-3862

Medium priority

Some fixes available 1 of 11

The MarkStack assignment operator, part of the JavaScript engine, could access uninitialized memory if it were used in a self-assignment. This vulnerability affects Firefox < 125.

8 affected packages

firefox, mozjs102, mozjs38, mozjs52, mozjs68...

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox — Not affected Not affected Fixed —
mozjs102 — Ignored Ignored Not in release —
mozjs38 — Not in release Not in release Not in release Ignored
mozjs52 — Not in release Not in release Ignored Ignored
mozjs68 — Not in release Not in release Ignored —
mozjs78 — Not in release Ignored Not in release —
mozjs91 — Not in release Ignored Not in release —
thunderbird — Not affected Not affected Not in release —
Show all 8 packages Show less packages

CVE-2024-3861

Medium priority

Some fixes available 4 of 13

If an AlignedBuffer were assigned to itself, the subsequent self-move could result in an incorrect reference count and later use-after-free. This vulnerability affects Firefox < 125, Firefox ESR < 115.10, and Thunderbird < 115.10.

8 affected packages

firefox, mozjs102, mozjs38, mozjs52, mozjs68...

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox — Not affected Not affected Fixed —
mozjs102 — Ignored Ignored Not in release —
mozjs38 — Not in release Not in release Not in release Ignored
mozjs52 — Not in release Not in release Ignored Ignored
mozjs68 — Not in release Not in release Ignored —
mozjs78 — Not in release Ignored Not in release —
mozjs91 — Not in release Ignored Not in release —
thunderbird — Not affected Fixed Fixed —
Show all 8 packages Show less packages

CVE-2024-3860

Medium priority

Some fixes available 1 of 11

An out-of-memory condition during object initialization could result in an empty shape list. If the JIT subsequently traced the object it would crash. This vulnerability affects Firefox < 125.

8 affected packages

firefox, mozjs102, mozjs38, mozjs52, mozjs68...

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox — Not affected Not affected Fixed —
mozjs102 — Ignored Ignored Not in release —
mozjs38 — Not in release Not in release Not in release Ignored
mozjs52 — Not in release Not in release Ignored Ignored
mozjs68 — Not in release Not in release Ignored —
mozjs78 — Not in release Ignored Not in release —
mozjs91 — Not in release Ignored Not in release —
thunderbird — Not affected Not affected Not in release —
Show all 8 packages Show less packages

CVE-2024-3859

Medium priority

Some fixes available 4 of 13

On 32-bit versions there were integer-overflows that led to an out-of-bounds-read that potentially could be triggered by a malformed OpenType font. This vulnerability affects Firefox < 125, Firefox ESR < 115.10, and Thunderbird < 115.10.

8 affected packages

firefox, mozjs102, mozjs38, mozjs52, mozjs68...

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox — Not affected Not affected Fixed —
mozjs102 — Ignored Ignored Not in release —
mozjs38 — Not in release Not in release Not in release Ignored
mozjs52 — Not in release Not in release Ignored Ignored
mozjs68 — Not in release Not in release Ignored —
mozjs78 — Not in release Ignored Not in release —
mozjs91 — Not in release Ignored Not in release —
thunderbird — Not affected Fixed Fixed —
Show all 8 packages Show less packages

CVE-2024-3858

Medium priority

Some fixes available 1 of 11

It was possible to mutate a JavaScript object so that the JIT could crash while tracing it. This vulnerability affects Firefox < 125.

8 affected packages

firefox, mozjs102, mozjs38, mozjs52, mozjs68...

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox — Not affected Not affected Fixed —
mozjs102 — Ignored Ignored Not in release —
mozjs38 — Not in release Not in release Not in release Ignored
mozjs52 — Not in release Not in release Ignored Ignored
mozjs68 — Not in release Not in release Ignored —
mozjs78 — Not in release Ignored Not in release —
mozjs91 — Not in release Ignored Not in release —
thunderbird — Not affected Not affected Not in release —
Show all 8 packages Show less packages

CVE-2024-3857

Medium priority

Some fixes available 4 of 13

The JIT created incorrect code for arguments in certain cases. This led to potential use-after-free crashes during garbage collection. This vulnerability affects Firefox < 125, Firefox ESR < 115.10, and Thunderbird < 115.10.

8 affected packages

firefox, mozjs102, mozjs38, mozjs52, mozjs68...

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox — Not affected Not affected Fixed —
mozjs102 — Ignored Ignored Not in release —
mozjs38 — Not in release Not in release Not in release Ignored
mozjs52 — Not in release Not in release Ignored Ignored
mozjs68 — Not in release Not in release Ignored —
mozjs78 — Not in release Ignored Not in release —
mozjs91 — Not in release Ignored Not in release —
thunderbird — Not affected Fixed Fixed —
Show all 8 packages Show less packages

CVE-2024-3856

Medium priority

Some fixes available 1 of 11

A use-after-free could occur during WASM execution if garbage collection ran during the creation of an array. This vulnerability affects Firefox < 125.

8 affected packages

firefox, mozjs102, mozjs38, mozjs52, mozjs68...

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox — Not affected Not affected Fixed —
mozjs102 — Ignored Ignored Not in release —
mozjs38 — Not in release Not in release Not in release Ignored
mozjs52 — Not in release Not in release Ignored Ignored
mozjs68 — Not in release Not in release Ignored —
mozjs78 — Not in release Ignored Not in release —
mozjs91 — Not in release Ignored Not in release —
thunderbird — Not affected Not affected Not in release —
Show all 8 packages Show less packages

CVE-2024-3855

Medium priority

Some fixes available 1 of 11

In certain cases the JIT incorrectly optimized MSubstr operations, which led to out-of-bounds reads. This vulnerability affects Firefox < 125.

8 affected packages

firefox, mozjs102, mozjs38, mozjs52, mozjs68...

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox — Not affected Not affected Fixed —
mozjs102 — Ignored Ignored Not in release —
mozjs38 — Not in release Not in release Not in release Ignored
mozjs52 — Not in release Not in release Ignored Ignored
mozjs68 — Not in release Not in release Ignored —
mozjs78 — Not in release Ignored Not in release —
mozjs91 — Not in release Ignored Not in release —
thunderbird — Not affected Not affected Not in release —
Show all 8 packages Show less packages

CVE-2024-3854

Medium priority

Some fixes available 4 of 13

In some code patterns the JIT incorrectly optimized switch statements and generated code with out-of-bounds-reads. This vulnerability affects Firefox < 125, Firefox ESR < 115.10, and Thunderbird < 115.10.

8 affected packages

firefox, mozjs102, mozjs38, mozjs52, mozjs68...

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox — Not affected Not affected Fixed —
mozjs102 — Ignored Ignored Not in release —
mozjs38 — Not in release Not in release Not in release Ignored
mozjs52 — Not in release Not in release Ignored Ignored
mozjs68 — Not in release Not in release Ignored —
mozjs78 — Not in release Ignored Not in release —
mozjs91 — Not in release Ignored Not in release —
thunderbird — Not affected Fixed Fixed —
Show all 8 packages Show less packages