Search CVE reports
41 – 50 of 31401 results
CVE-2024-10464
Medium priorityRepeated writes to history interface attributes could have been used to cause a Denial of Service condition in the browser. This was addressed by introducing rate-limiting to this API. This vulnerability affects Firefox < 132,...
9 affected packages
firefox, mozjs102, mozjs115, mozjs38, mozjs52...
Package | 18.04 LTS |
---|---|
firefox | — |
mozjs102 | — |
mozjs115 | — |
mozjs38 | Needs evaluation |
mozjs52 | Ignored |
mozjs68 | — |
mozjs78 | — |
mozjs91 | — |
thunderbird | — |
CVE-2024-10463
Medium priorityVideo frames could have been leaked between origins in some situations. This vulnerability affects Firefox < 132, Firefox ESR < 128.4, Firefox ESR < 115.17, Thunderbird < 128.4, and Thunderbird < 132.
9 affected packages
firefox, mozjs102, mozjs115, mozjs38, mozjs52...
Package | 18.04 LTS |
---|---|
firefox | — |
mozjs102 | — |
mozjs115 | — |
mozjs38 | Needs evaluation |
mozjs52 | Ignored |
mozjs68 | — |
mozjs78 | — |
mozjs91 | — |
thunderbird | — |
CVE-2024-10462
Medium priorityTruncation of a long URL could have allowed origin spoofing in a permission prompt. This vulnerability affects Firefox < 132, Firefox ESR < 128.4, Thunderbird < 128.4, and Thunderbird < 132.
9 affected packages
firefox, mozjs102, mozjs115, mozjs38, mozjs52...
Package | 18.04 LTS |
---|---|
firefox | — |
mozjs102 | — |
mozjs115 | — |
mozjs38 | Needs evaluation |
mozjs52 | Ignored |
mozjs68 | — |
mozjs78 | — |
mozjs91 | — |
thunderbird | — |
CVE-2024-10461
Medium priorityIn multipart/x-mixed-replace responses, `Content-Disposition: attachment` in the response header was not respected and did not force a download, which could allow XSS attacks. This vulnerability affects Firefox < 132, Firefox ESR...
9 affected packages
firefox, mozjs102, mozjs115, mozjs38, mozjs52...
Package | 18.04 LTS |
---|---|
firefox | — |
mozjs102 | — |
mozjs115 | — |
mozjs38 | Needs evaluation |
mozjs52 | Ignored |
mozjs68 | — |
mozjs78 | — |
mozjs91 | — |
thunderbird | — |
CVE-2024-10460
Medium priorityThe origin of an external protocol handler prompt could have been obscured using a data: URL within an `iframe`. This vulnerability affects Firefox < 132, Firefox ESR < 128.4, Thunderbird < 128.4, and Thunderbird < 132.
9 affected packages
firefox, mozjs102, mozjs115, mozjs38, mozjs52...
Package | 18.04 LTS |
---|---|
firefox | — |
mozjs102 | — |
mozjs115 | — |
mozjs38 | Needs evaluation |
mozjs52 | Ignored |
mozjs68 | — |
mozjs78 | — |
mozjs91 | — |
thunderbird | — |
CVE-2024-10459
Medium priorityAn attacker could have caused a use-after-free when accessibility was enabled, leading to a potentially exploitable crash. This vulnerability affects Firefox < 132, Firefox ESR < 128.4, Firefox ESR < 115.17, Thunderbird < 128.4,...
9 affected packages
firefox, mozjs102, mozjs115, mozjs38, mozjs52...
Package | 18.04 LTS |
---|---|
firefox | — |
mozjs102 | — |
mozjs115 | — |
mozjs38 | Needs evaluation |
mozjs52 | Ignored |
mozjs68 | — |
mozjs78 | — |
mozjs91 | — |
thunderbird | — |
CVE-2024-10458
Medium priorityA permission leak could have occurred from a trusted site to an untrusted site via `embed` or `object` elements. This vulnerability affects Firefox < 132, Firefox ESR < 128.4, Firefox ESR < 115.17, Thunderbird < 128.4,...
9 affected packages
firefox, mozjs102, mozjs115, mozjs38, mozjs52...
Package | 18.04 LTS |
---|---|
firefox | — |
mozjs102 | — |
mozjs115 | — |
mozjs38 | Needs evaluation |
mozjs52 | Ignored |
mozjs68 | — |
mozjs78 | — |
mozjs91 | — |
thunderbird | — |
CVE-2024-49761
Medium priorityREXML is an XML toolkit for Ruby. The REXML gem before 3.3.9 has a ReDoS vulnerability when it parses an XML that has many digits between &# and x...; in a hex numeric character reference (&#x...;). This does not happen with Ruby...
7 affected packages
jruby, ruby2.3, ruby2.5, ruby2.7, ruby3.0...
Package | 18.04 LTS |
---|---|
jruby | Needs evaluation |
ruby2.3 | — |
ruby2.5 | Needs evaluation |
ruby2.7 | — |
ruby3.0 | — |
ruby3.2 | — |
ruby3.3 | — |
CVE-2024-45802
Medium prioritySquid is an open source caching proxy for the Web supporting HTTP, HTTPS, FTP, and more. Due to Input Validation, Premature Release of Resource During Expected Lifetime, and Missing Release of Resource after Effective Lifetime...
2 affected packages
squid, squid3
Package | 18.04 LTS |
---|---|
squid | — |
squid3 | Needs evaluation |
CVE-2024-8013
Medium priorityA bug in query analysis of certain complex self-referential $lookup subpipelines may result in literal values in expressions for encrypted fields to be sent to the server as plaintext instead of ciphertext. Should this occur, no...
1 affected packages
mongodb
Package | 18.04 LTS |
---|---|
mongodb | Needs evaluation |