Your submission was sent successfully! Close

You have successfully unsubscribed! Close

Thank you for signing up for our newsletter!
In these regular emails you will find the latest updates about Ubuntu and upcoming events where you can meet our team.Close

Search CVE reports


Toggle filters

71 – 80 of 30862 results

Status is adjusted based on your filters.


CVE-2024-9399

Medium priority
Needs evaluation

A website configured to initiate a specially crafted WebTransport session could crash the Firefox process leading to a denial of service condition. This vulnerability affects Firefox < 131, Firefox ESR < 128.3, Thunderbird <...

9 affected packages

firefox, mozjs102, mozjs115, mozjs38, mozjs52...

Package 18.04 LTS
firefox
mozjs102
mozjs115
mozjs38 Needs evaluation
mozjs52 Ignored
mozjs68
mozjs78
mozjs91
thunderbird
Show all 9 packages Show less packages

CVE-2024-9398

Medium priority
Needs evaluation

By checking the result of calls to `window.open` with specifically set protocol handlers, an attacker could determine if the application which implements that protocol handler is installed. This vulnerability affects Firefox <...

9 affected packages

firefox, mozjs102, mozjs115, mozjs38, mozjs52...

Package 18.04 LTS
firefox
mozjs102
mozjs115
mozjs38 Needs evaluation
mozjs52 Ignored
mozjs68
mozjs78
mozjs91
thunderbird
Show all 9 packages Show less packages

CVE-2024-9397

Medium priority
Needs evaluation

A missing delay in directory upload UI could have made it possible for an attacker to trick a user into granting permission via clickjacking. This vulnerability affects Firefox < 131, Firefox ESR < 128.3, Thunderbird < 128.3, and...

9 affected packages

firefox, mozjs102, mozjs115, mozjs38, mozjs52...

Package 18.04 LTS
firefox
mozjs102
mozjs115
mozjs38 Needs evaluation
mozjs52 Ignored
mozjs68
mozjs78
mozjs91
thunderbird
Show all 9 packages Show less packages

CVE-2024-9396

Medium priority
Needs evaluation

It is currently unknown if this issue is exploitable but a condition may arise where the structured clone of certain objects could lead to memory corruption. This vulnerability affects Firefox < 131, Firefox ESR <...

9 affected packages

firefox, mozjs102, mozjs115, mozjs38, mozjs52...

Package 18.04 LTS
firefox
mozjs102
mozjs115
mozjs38 Needs evaluation
mozjs52 Ignored
mozjs68
mozjs78
mozjs91
thunderbird
Show all 9 packages Show less packages

CVE-2024-9394

Medium priority
Needs evaluation

An attacker could, via a specially crafted multipart response, execute arbitrary JavaScript under the `resource://devtools` origin. This could allow them to access cross-origin JSON content. This access is limited to "same site"...

9 affected packages

firefox, mozjs102, mozjs115, mozjs38, mozjs52...

Package 18.04 LTS
firefox
mozjs102
mozjs115
mozjs38 Needs evaluation
mozjs52 Ignored
mozjs68
mozjs78
mozjs91
thunderbird
Show all 9 packages Show less packages

CVE-2024-9393

Medium priority
Needs evaluation

An attacker could, via a specially crafted multipart response, execute arbitrary JavaScript under the `resource://pdf.js` origin. This could allow them to access cross-origin PDF content. This access is limited to "same site"...

9 affected packages

firefox, mozjs102, mozjs115, mozjs38, mozjs52...

Package 18.04 LTS
firefox
mozjs102
mozjs115
mozjs38 Needs evaluation
mozjs52 Ignored
mozjs68
mozjs78
mozjs91
thunderbird
Show all 9 packages Show less packages

CVE-2024-9392

Medium priority
Needs evaluation

A compromised content process could have allowed for the arbitrary loading of cross-origin pages. This vulnerability affects Firefox < 131, Firefox ESR < 128.3, Firefox ESR < 115.16, Thunderbird < 128.3, and Thunderbird < 131.

9 affected packages

firefox, mozjs102, mozjs115, mozjs38, mozjs52...

Package 18.04 LTS
firefox
mozjs102
mozjs115
mozjs38 Needs evaluation
mozjs52 Ignored
mozjs68
mozjs78
mozjs91
thunderbird
Show all 9 packages Show less packages

CVE-2024-47611

Medium priority
Not affected

XZ Utils provide a general-purpose data-compression library plus command-line tools. When built for native Windows (MinGW-w64 or MSVC), the command line tools from XZ Utils 5.6.2 and older have a command line argument injection...

1 affected packages

xz-utils

Package 18.04 LTS
xz-utils Not affected
Show less packages

CVE-2024-9403

Medium priority
Needs evaluation

Memory safety bugs present in Firefox 130. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects...

9 affected packages

firefox, mozjs102, mozjs115, mozjs38, mozjs52...

Package 18.04 LTS
firefox
mozjs102
mozjs115
mozjs38 Needs evaluation
mozjs52 Ignored
mozjs68
mozjs78
mozjs91
thunderbird
Show all 9 packages Show less packages

CVE-2024-9395

Medium priority
Needs evaluation

A specially crafted filename containing a large number of spaces could obscure the file's extension when displayed in the download dialog. *This bug only affects Firefox for Android. Other versions of Firefox are unaffected.* This...

9 affected packages

firefox, mozjs102, mozjs115, mozjs38, mozjs52...

Package 18.04 LTS
firefox
mozjs102
mozjs115
mozjs38 Needs evaluation
mozjs52 Ignored
mozjs68
mozjs78
mozjs91
thunderbird
Show all 9 packages Show less packages