Search CVE reports


Toggle filters

1201 – 1210 of 1493 results


CVE-2021-23962

Medium priority

Some fixes available 11 of 23

Incorrect use of the '<RowCountChanged>' method could have led to a user-after-poison and a potentially exploitable crash. This vulnerability affects Firefox < 85.

6 affected packages

firefox, mozjs38, mozjs52, mozjs60, mozjs68, mozjs78

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox — Fixed Fixed Fixed Fixed
mozjs38 — Not in release Not in release Not in release Ignored
mozjs52 — Not in release Not in release Ignored Ignored
mozjs60 — Not in release Not in release Not in release Not in release
mozjs68 — Not in release Not in release Ignored Not in release
mozjs78 — Not in release Ignored Not in release Not in release
Show less packages

CVE-2021-23961

Medium priority

Some fixes available 21 of 33

Further techniques that built on the slipstream research combined with a malicious webpage could have exposed both an internal network's hosts as well as services running on the user's local machine. This vulnerability affects...

7 affected packages

firefox, mozjs38, mozjs52, mozjs60, mozjs68...

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox — Fixed Fixed Fixed Fixed
mozjs38 — Not in release Not in release Not in release Ignored
mozjs52 — Not in release Not in release Ignored Ignored
mozjs60 — Not in release Not in release Not in release Not in release
mozjs68 — Not in release Not in release Ignored Not in release
mozjs78 — Not in release Ignored Not in release Not in release
thunderbird — Fixed Fixed Fixed Fixed
Show all 7 packages Show less packages

CVE-2021-23960

Medium priority

Some fixes available 21 of 31

Performing garbage collection on re-declared JavaScript variables resulted in a user-after-poison, and a potentially exploitable crash. This vulnerability affects Firefox < 85, Thunderbird < 78.7, and Firefox ESR < 78.7.

8 affected packages

mozjs38, mozjs52, firefox, firefox-esr, mozjs60...

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mozjs38 — Not in release Not in release Not in release Ignored
mozjs52 — Not in release Not in release Ignored Ignored
firefox — Fixed Fixed Fixed Fixed
firefox-esr — Not in release Not in release Not in release Not in release
mozjs60 — Not in release Not in release Not in release Not in release
mozjs68 — Not in release Not in release Ignored Not in release
mozjs78 — Not in release Ignored Not in release Not in release
thunderbird — Fixed Fixed Fixed Fixed
Show all 8 packages Show less packages

CVE-2021-23958

Medium priority

Some fixes available 11 of 23

The browser could have been confused into transferring a screen sharing state into another tab, which would leak unintended information. This vulnerability affects Firefox < 85.

6 affected packages

firefox, mozjs38, mozjs52, mozjs60, mozjs68, mozjs78

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox — Fixed Fixed Fixed Fixed
mozjs38 — Not in release Not in release Not in release Ignored
mozjs52 — Not in release Not in release Ignored Ignored
mozjs60 — Not in release Not in release Not in release Not in release
mozjs68 — Not in release Not in release Ignored Not in release
mozjs78 — Not in release Ignored Not in release Not in release
Show less packages

CVE-2021-23956

Medium priority

Some fixes available 11 of 23

An ambiguous file picker design could have confused users who intended to select and upload a single file into uploading a whole directory. This was addressed by adding a new prompt. This vulnerability affects Firefox < 85.

6 affected packages

firefox, mozjs38, mozjs52, mozjs60, mozjs68, mozjs78

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox — Fixed Fixed Fixed Fixed
mozjs38 — Not in release Not in release Not in release Ignored
mozjs52 — Not in release Not in release Ignored Ignored
mozjs60 — Not in release Not in release Not in release Not in release
mozjs68 — Not in release Not in release Ignored Not in release
mozjs78 — Not in release Ignored Not in release Not in release
Show less packages

CVE-2021-23955

Medium priority

Some fixes available 11 of 23

The browser could have been confused into transferring a pointer lock state into another tab, which could have lead to clickjacking attacks. This vulnerability affects Firefox < 85.

6 affected packages

firefox, mozjs38, mozjs52, mozjs60, mozjs68, mozjs78

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox — Fixed Fixed Fixed Fixed
mozjs38 — Not in release Not in release Not in release Ignored
mozjs52 — Not in release Not in release Ignored Ignored
mozjs60 — Not in release Not in release Not in release Not in release
mozjs68 — Not in release Not in release Ignored Not in release
mozjs78 — Not in release Ignored Not in release Not in release
Show less packages

CVE-2021-23954

Medium priority

Some fixes available 21 of 31

Using the new logical assignment operators in a JavaScript switch statement could have caused a type confusion, leading to a memory corruption and a potentially exploitable crash. This vulnerability affects Firefox <...

8 affected packages

mozjs38, mozjs52, firefox, firefox-esr, mozjs60...

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mozjs38 — Not in release Not in release Not in release Ignored
mozjs52 — Not in release Not in release Ignored Ignored
firefox — Fixed Fixed Fixed Fixed
firefox-esr — Not in release Not in release Not in release Not in release
mozjs60 — Not in release Not in release Not in release Not in release
mozjs68 — Not in release Not in release Ignored Not in release
mozjs78 — Not in release Ignored Not in release Not in release
thunderbird — Fixed Fixed Fixed Fixed
Show all 8 packages Show less packages

CVE-2021-23953

Medium priority

Some fixes available 21 of 31

If a user clicked into a specifically crafted PDF, the PDF reader could be confused into leaking cross-origin information, when said information is served as chunked data. This vulnerability affects Firefox < 85, Thunderbird <...

8 affected packages

mozjs38, mozjs52, firefox, firefox-esr, mozjs60...

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mozjs38 — Not in release Not in release Not in release Ignored
mozjs52 — Not in release Not in release Ignored Ignored
firefox — Fixed Fixed Fixed Fixed
firefox-esr — Not in release Not in release Not in release Not in release
mozjs60 — Not in release Not in release Not in release Not in release
mozjs68 — Not in release Not in release Ignored Not in release
mozjs78 — Not in release Ignored Not in release Not in release
thunderbird — Fixed Fixed Fixed Fixed
Show all 8 packages Show less packages

CVE-2020-16044

Medium priority

Some fixes available 21 of 33

Use after free in WebRTC in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to potentially exploit heap corruption via a crafted SCTP packet.

7 affected packages

firefox, mozjs38, mozjs52, mozjs60, mozjs68...

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox — Fixed Fixed Fixed Fixed
mozjs38 — Not in release Not in release Not in release Ignored
mozjs52 — Not in release Not in release Ignored Ignored
mozjs60 — Not in release Not in release Not in release Not in release
mozjs68 — Not in release Not in release Ignored Not in release
mozjs78 — Not in release Ignored Not in release Not in release
thunderbird — Fixed Fixed Fixed Fixed
Show all 7 packages Show less packages

CVE-2020-35112

Low priority
Ignored

If a user downloaded a file lacking an extension on Windows, and then "Open"-ed it from the downloads panel, if there was an executable file in the downloads directory with the same name but with an executable extension (such as...

7 affected packages

firefox, mozjs38, mozjs52, mozjs60, mozjs68...

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox — Not affected Not affected Not in release Not affected
mozjs38 — Not in release Not in release Not in release Ignored
mozjs52 — Not in release Not in release Ignored Ignored
mozjs60 — Not in release Not in release Not in release Not in release
mozjs68 — Not in release Not in release Ignored Not in release
mozjs78 — Not in release Ignored Not in release Not in release
thunderbird — Not affected Not affected Not in release Not affected
Show all 7 packages Show less packages