‼ CVE-2023-29537 ‼
📖 Read
via "National Vulnerability Database".
Multiple race conditions in the font initialization could have led to memory corruption and execution of attacker-controlled code. This vulnerability affects Firefox for Android < 112, Firefox < 112, and Focus for Android < 112.📖 Read
via "National Vulnerability Database".
‼ CVE-2023-29538 ‼
📖 Read
via "National Vulnerability Database".
Under specific circumstances a WebExtension may have received a <code>jar:file:///</code> URI instead of a <code>moz-extension:///</code> URI during a load request. This leaked directory paths on the user's machine. This vulnerability affects Firefox for Android < 112, Firefox < 112, and Focus for Android < 112.📖 Read
via "National Vulnerability Database".
‼ CVE-2023-25741 ‼
📖 Read
via "National Vulnerability Database".
When dragging and dropping an image cross-origin, the image's size could potentially be leaked. This behavior was shipped in 109 and caused web compatibility problems as well as this security concern, so the behavior was disabled until further review. This vulnerability affects Firefox < 110.📖 Read
via "National Vulnerability Database".
‼ CVE-2023-25746 ‼
📖 Read
via "National Vulnerability Database".
Mozilla developers Philipp and Gabriele Svelto reported memory safety bugs present in Firefox ESR 102.7. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Thunderbird < 102.8 and Firefox ESR < 102.8.📖 Read
via "National Vulnerability Database".
‼ CVE-2023-0616 ‼
📖 Read
via "National Vulnerability Database".
If a MIME email combines OpenPGP and OpenPGP MIME data in a certain way Thunderbird repeatedly attempts to process and display the message, which could cause Thunderbird's user interface to lock up and no longer respond to the user's actions. An attacker could send a crafted message with this structure to attempt a DoS attack. This vulnerability affects Thunderbird < 102.8.📖 Read
via "National Vulnerability Database".
‼ CVE-2023-23605 ‼
📖 Read
via "National Vulnerability Database".
Mozilla developers and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 108 and Firefox ESR 102.6. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 109, Thunderbird < 102.7, and Firefox ESR < 102.7.📖 Read
via "National Vulnerability Database".
‼ CVE-2023-32205 ‼
📖 Read
via "National Vulnerability Database".
In multiple cases browser prompts could have been obscured by popups controlled by content. These could have led to potential user confusion and spoofing attacks. This vulnerability affects Firefox < 113, Firefox ESR < 102.11, and Thunderbird < 102.11.📖 Read
via "National Vulnerability Database".
‼ CVE-2023-29540 ‼
📖 Read
via "National Vulnerability Database".
Using a redirect embedded into <code>sourceMappingUrls</code> could allow for navigation to external protocol links in sandboxed iframes without <code>allow-top-navigation-to-custom-protocols</code>. This vulnerability affects Firefox for Android < 112, Firefox < 112, and Focus for Android < 112.📖 Read
via "National Vulnerability Database".
‼ CVE-2023-29541 ‼
📖 Read
via "National Vulnerability Database".
Firefox did not properly handle downloads of files ending in <code>.desktop</code>, which can be interpreted to run attacker-controlled commands. <br>*This bug only affects Firefox for Linux on certain Distributions. Other operating systems are unaffected, and Mozilla is unable to enumerate all affected Linux Distributions.*. This vulnerability affects Firefox < 112, Focus for Android < 112, Firefox ESR < 102.10, Firefox for Android < 112, and Thunderbird < 102.10.📖 Read
via "National Vulnerability Database".
‼ CVE-2023-29547 ‼
📖 Read
via "National Vulnerability Database".
When a secure cookie existed in the Firefox cookie jar an insecure cookie for the same domain could have been created, when it should have silently failed. This could have led to a desynchronization in expected results when reading from the secure cookie. This vulnerability affects Firefox for Android < 112, Firefox < 112, and Focus for Android < 112.📖 Read
via "National Vulnerability Database".
❤1
‼ CVE-2023-32206 ‼
📖 Read
via "National Vulnerability Database".
An out-of-bound read could have led to a crash in the RLBox Expat driver. This vulnerability affects Firefox < 113, Firefox ESR < 102.11, and Thunderbird < 102.11.📖 Read
via "National Vulnerability Database".
‼ CVE-2023-25730 ‼
📖 Read
via "National Vulnerability Database".
A background script invoking <code>requestFullscreen</code> and then blocking the main thread could force the browser into fullscreen mode indefinitely, resulting in potential user confusion or spoofing attacks. This vulnerability affects Firefox < 110, Thunderbird < 102.8, and Firefox ESR < 102.8.📖 Read
via "National Vulnerability Database".
‼ CVE-2023-32215 ‼
📖 Read
via "National Vulnerability Database".
Mozilla developers and community members Gabriele Svelto, Andrew Osmond, Emily McDonough, Sebastian Hengst, Andrew McCreight and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 112 and Firefox ESR 102.10. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 113, Firefox ESR < 102.11, and Thunderbird < 102.11.📖 Read
via "National Vulnerability Database".
‼ CVE-2023-28161 ‼
📖 Read
via "National Vulnerability Database".
If temporary "one-time" permissions, such as the ability to use the Camera, were granted to a document loaded using a file: URL, that permission persisted in that tab for all other documents loaded from a file: URL. This is potentially dangerous if the local files came from different sources, such as in a download directory. This vulnerability affects Firefox < 111.📖 Read
via "National Vulnerability Database".
🕴 'PostalFurious' SMS Attacks Target UAE Citizens for Data Theft 🕴
📖 Read
via "Dark Reading".
SMS campaigns targeting members of the public in the United Arab Emirates have been detected.📖 Read
via "Dark Reading".
Dark Reading
'PostalFurious' SMS Attacks Target UAE Citizens for Data Theft
SMS campaigns targeting members of the public in the United Arab Emirates have been detected.
‼ CVE-2023-3075 ‼
📖 Read
via "National Vulnerability Database".
Cross-Site Request Forgery (CSRF) in GitHub repository tsolucio/corebos prior to 8.📖 Read
via "National Vulnerability Database".
‼ CVE-2023-3074 ‼
📖 Read
via "National Vulnerability Database".
Cross-site Scripting (XSS) - Stored in GitHub repository tsolucio/corebos prior to 8.📖 Read
via "National Vulnerability Database".
‼ CVE-2023-3073 ‼
📖 Read
via "National Vulnerability Database".
Cross-site Scripting (XSS) - Stored in GitHub repository tsolucio/corebos prior to 8.📖 Read
via "National Vulnerability Database".
🕴 PyPI's 2FA Requirements Don't Go Far Enough, Researchers Say 🕴
📖 Read
via "Dark Reading".
The Python Package Index will require developers to better secure their accounts as cyberattacks ramp up, but protecting the software supply chain will take more than that.📖 Read
via "Dark Reading".
Dark Reading
PyPI's 2FA Requirements Don't Go Far Enough, Researchers Say
The Python Package Index will require developers to better secure their accounts as cyberattacks ramp up, but protecting the software supply chain will take more than that.
‼ CVE-2023-33761 ‼
📖 Read
via "National Vulnerability Database".
eMedia Consulting simpleRedak up to v2.47.23.05 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the component /view/cb/format_642.php.📖 Read
via "National Vulnerability Database".
‼ CVE-2023-33670 ‼
📖 Read
via "National Vulnerability Database".
Tenda AC8V4.0-V16.03.34.06 was discovered to contain a stack overflow via the time parameter in the sub_4a79ec function.📖 Read
via "National Vulnerability Database".