Search CVE reports
1261 – 1270 of 3250 results
Some fixes available 21 of 27
Mozilla developers and community members reported memory safety bugs present in Firefox 81 and Firefox ESR 78.3. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could...
6 affected packages
firefox, mozjs38, mozjs52, mozjs60, mozjs68, thunderbird
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| firefox | — | Fixed | Fixed | Fixed | Fixed |
| mozjs38 | — | Not in release | Not in release | Not in release | Ignored |
| mozjs52 | — | Not in release | Not in release | Ignored | Ignored |
| mozjs60 | — | Not in release | Not in release | Not in release | Not in release |
| mozjs68 | — | Not in release | Not in release | Ignored | Not in release |
| thunderbird | — | Fixed | Fixed | Fixed | Fixed |
Some fixes available 11 of 17
When a link to an external protocol was clicked, a prompt was presented that allowed the user to choose what application to open it in. An attacker could induce that prompt to be associated with an origin they didn't control,...
5 affected packages
firefox, mozjs38, mozjs52, mozjs60, mozjs68
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| firefox | — | Fixed | Fixed | Fixed | Fixed |
| mozjs38 | — | Not in release | Not in release | Not in release | Ignored |
| mozjs52 | — | Not in release | Not in release | Ignored | Ignored |
| mozjs60 | — | Not in release | Not in release | Not in release | Not in release |
| mozjs68 | — | Not in release | Not in release | Ignored | Not in release |
Some fixes available 11 of 17
When multiple WASM threads had a reference to a module, and were looking up exported functions, one WASM thread could have overwritten another's entry in a shared stub table, resulting in a potentially exploitable crash....
5 affected packages
firefox, mozjs38, mozjs52, mozjs60, mozjs68
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| firefox | — | Fixed | Fixed | Fixed | Fixed |
| mozjs38 | — | Not in release | Not in release | Not in release | Ignored |
| mozjs52 | — | Not in release | Not in release | Ignored | Ignored |
| mozjs60 | — | Not in release | Not in release | Not in release | Not in release |
| mozjs68 | — | Not in release | Not in release | Ignored | Not in release |
Some fixes available 11 of 17
If a valid external protocol handler was referenced in an image tag, the resulting broken image size could be distinguished from a broken image size of a non-existent protocol handler. This allowed an attacker to successfully...
5 affected packages
firefox, mozjs38, mozjs52, mozjs60, mozjs68
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| firefox | — | Fixed | Fixed | Fixed | Fixed |
| mozjs38 | — | Not in release | Not in release | Not in release | Ignored |
| mozjs52 | — | Not in release | Not in release | Ignored | Ignored |
| mozjs60 | — | Not in release | Not in release | Not in release | Not in release |
| mozjs68 | — | Not in release | Not in release | Ignored | Not in release |
Some fixes available 15 of 31
Crossbeam is a set of tools for concurrent programming. In crossbeam-channel before version 0.4.4, the bounded channel incorrectly assumes that `Vec::from_iter` has allocated capacity that same as the number of iterator elements....
6 affected packages
rust-crossbeam, firefox, mozjs38, mozjs52, mozjs60, mozjs68
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| rust-crossbeam | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Not in release |
| firefox | Fixed | Fixed | Fixed | Fixed | Fixed |
| mozjs38 | Not in release | Not in release | Not in release | Not in release | Ignored |
| mozjs52 | Not in release | Not in release | Not in release | Ignored | Ignored |
| mozjs60 | Not in release | Not in release | Not in release | Not in release | Not in release |
| mozjs68 | Not in release | Not in release | Not in release | Ignored | Not in release |
Heap buffer overflow in Freetype in Google Chrome prior to 86.0.4240.111 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
18 affected packages
android, chromium-browser, firefox, freetype, godot...
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| android | — | Not in release | Not in release | Not in release | Not in release |
| chromium-browser | — | Not affected | Not affected | Not in release | Fixed |
| firefox | — | Not affected | Not affected | Not in release | Not affected |
| freetype | — | Fixed | Fixed | Fixed | Fixed |
| godot | — | Not affected | Not affected | Not affected | Not in release |
| graphicsmagick | — | Not affected | Not affected | Not affected | Not affected |
| musescore | — | Not in release | Not in release | Not affected | Not affected |
| openjdk-12 | — | Not in release | Not in release | Not in release | Not in release |
| openjdk-13 | — | Not in release | Not in release | Not affected | Not in release |
| openjdk-15 | — | Not in release | Not in release | Not in release | Not in release |
| openjdk-lts | — | Not affected | Not affected | Not affected | Not affected |
| oxide-qt | — | Not in release | Not in release | Not in release | Not in release |
| paraview | — | Not affected | Not affected | Not affected | Not affected |
| qtbase-opensource-src | — | Not affected | Not affected | Not affected | Not affected |
| qtbase-opensource-src-gles | — | Not affected | Not affected | Not affected | Not in release |
| texlive-bin | — | Not affected | Not affected | Not affected | Not affected |
| texmaker | — | Not affected | Not affected | Not affected | Not affected |
| thunderbird | — | Not affected | Not affected | Not in release | Not affected |
Some fixes available 23 of 29
Use after free in WebRTC in Google Chrome prior to 86.0.4240.75 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
7 affected packages
chromium-browser, firefox, mozjs38, mozjs52, mozjs60...
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| chromium-browser | — | Not affected | Not affected | Not in release | Fixed |
| firefox | — | Fixed | Fixed | Fixed | Fixed |
| mozjs38 | — | Not in release | Not in release | Not in release | Ignored |
| mozjs52 | — | Not in release | Not in release | Ignored | Ignored |
| mozjs60 | — | Not in release | Not in release | Not in release | Not in release |
| mozjs68 | — | Not in release | Not in release | Ignored | Not in release |
| thunderbird | — | Fixed | Fixed | Fixed | Fixed |
When aborting an operation, such as a fetch, an abort signal may be deleted while alerting the objects to be notified. This results in a use-after-free and we presume that with enough effort it could have been exploited to...
2 affected packages
firefox-esr, thunderbird
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| firefox-esr | — | — | Not in release | Not in release | Not in release |
| thunderbird | — | — | Not affected | Fixed | Fixed |
When processing a MAR update file, after the signature has been validated, an invalid name length could result in a heap overflow, leading to memory corruption and potentially arbitrary code execution. Within Firefox as released...
5 affected packages
firefox, mozjs38, mozjs52, mozjs60, mozjs68
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| firefox | — | Not affected | Not affected | Not in release | Not affected |
| mozjs38 | — | Not in release | Not in release | Not in release | Ignored |
| mozjs52 | — | Not in release | Not in release | Ignored | Ignored |
| mozjs60 | — | Not in release | Not in release | Not in release | Not in release |
| mozjs68 | — | Not in release | Not in release | Ignored | Not in release |
If Firefox is installed to a user-writable directory, the Mozilla Maintenance Service would execute updater.exe from the install location with system privileges. Although the Mozilla Maintenance Service does ensure that...
2 affected packages
firefox, thunderbird
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| firefox | — | — | — | Not in release | Not affected |
| thunderbird | — | — | — | Not in release | Not affected |