Mozilla Firefox是美国Mozilla基金会的一款开源Web浏览器。 Mozilla Firefox 127 版本存在安全漏洞,该漏洞源于可以防止用户在按下 Esc 键时退出 pointerlock,并将 select 元素中的自定义有效性通知覆盖在某些权限提示上。这可以用来迷惑用户,使其向网站授予非预期的权限。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Mozilla | Firefox | unspecified ~ 128 | - |
|
| Mozilla | Thunderbird | unspecified ~ 128 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2024-6614 | Incorrect listing of stack frames | |
| CVE-2024-6615 | Memory safety bugs fixed in Firefox 128 and Thunderbird 128 | |
| CVE-2024-6613 | Incorrect listing of stack frames | |
| CVE-2024-6611 | Incorrect handling of SameSite cookies | |
| CVE-2024-6612 | CSP violation leakage when using devtools | |
| CVE-2024-6608 | Cursor could be moved out of the viewport using pointerlock. | |
| CVE-2024-6609 | Memory corruption in NSS | |
| CVE-2024-6610 | Form validation popups could block exiting full-screen mode | |
| CVE-2024-6604 | Memory safety bugs fixed in Firefox 128, Firefox ESR 115.13, Thunderbird 128, and Thunderb | |
| CVE-2024-6606 | Out-of-bounds read in clipboard component | |
| CVE-2024-6605 | Firefox Android missed activation delay to prevent tapjacking | |
| CVE-2024-6601 | Race condition in permission assignment | |
| CVE-2024-6602 | Memory corruption in NSS | |
| CVE-2024-6603 | Memory corruption in thread creation | |
| CVE-2024-6600 | Memory corruption in WebGL API |
No comments yet