apk package
chainguard/firefox
pkg:apk/chainguard/firefox
Vulnerabilities (685)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2024-5699 | Cri | 9.8 | < 127.0.2-r0 | 127.0.2-r0 | Jun 11, 2024 | In violation of spec, cookie prefixes such as `__Secure` were being ignored if they were not correctly capitalized - by spec they should be checked with a case-insensitive comparison. This could have resulted in the browser not correctly honoring the behaviors specified by the pr | |
| CVE-2024-5698 | Med | 6.1 | < 127.0.2-r0 | 127.0.2-r0 | Jun 11, 2024 | By manipulating the fullscreen feature while opening a data-list, an attacker could have overlaid a text box over the address bar. This could have led to user confusion and possible spoofing attacks. This vulnerability affects Firefox < 127. | |
| CVE-2024-5697 | Med | 4.3 | < 127.0.2-r0 | 127.0.2-r0 | Jun 11, 2024 | A website was able to detect when a user took a screenshot of a page using the built-in Screenshot functionality in Firefox. This vulnerability affects Firefox < 127. | |
| CVE-2024-5696 | Hig | 8.6 | < 127.0.2-r0 | 127.0.2-r0 | Jun 11, 2024 | By manipulating the text in an `<input>` tag, an attacker could have caused corrupt memory leading to a potentially exploitable crash. This vulnerability affects Firefox < 127, Firefox ESR < 115.12, and Thunderbird < 115.12. | |
| CVE-2024-5695 | Cri | 9.8 | < 127.0.2-r0 | 127.0.2-r0 | Jun 11, 2024 | If an out-of-memory condition occurs at a specific point using allocations in the probabilistic heap checker, an assertion could have been triggered, and in rarer situations, memory corruption could have occurred. This vulnerability affects Firefox < 127. | |
| CVE-2024-5694 | Hig | 7.5 | < 127.0.2-r0 | 127.0.2-r0 | Jun 11, 2024 | An attacker could have caused a use-after-free in the JavaScript engine to read memory in the JavaScript string section of the heap. This vulnerability affects Firefox < 127. | |
| CVE-2024-5693 | Med | 6.1 | < 127.0.2-r0 | 127.0.2-r0 | Jun 11, 2024 | Offscreen Canvas did not properly track cross-origin tainting, which could be used to access image data from another site in violation of same-origin policy. This vulnerability affects Firefox < 127, Firefox ESR < 115.12, and Thunderbird < 115.12. | |
| CVE-2024-5692 | Med | 6.5 | < 127.0.2-r0 | 127.0.2-r0 | Jun 11, 2024 | On Windows 10, when using the 'Save As' functionality, an attacker could have tricked the browser into saving the file with a disallowed extension such as `.url` by including an invalid character in the extension. *Note:* This issue only affected Windows operating systems. Other | |
| CVE-2024-5691 | Med | 4.7 | < 127.0.2-r0 | 127.0.2-r0 | Jun 11, 2024 | By tricking the browser with a `X-Frame-Options` header, a sandboxed iframe could have presented a button that, if clicked by a user, would bypass restrictions to open a new window. This vulnerability affects Firefox < 127, Firefox ESR < 115.12, and Thunderbird < 115.12. | |
| CVE-2024-5690 | Med | 4.3 | < 127.0.2-r0 | 127.0.2-r0 | Jun 11, 2024 | By monitoring the time certain operations take, an attacker could have guessed which external protocol handlers were functional on a user's system. This vulnerability affects Firefox < 127, Firefox ESR < 115.12, and Thunderbird < 115.12. | |
| CVE-2024-5689 | Med | 4.3 | < 127.0.2-r0 | 127.0.2-r0 | Jun 11, 2024 | In addition to detecting when a user was taking a screenshot (XXX), a website was able to overlay the 'My Shots' button that appeared, and direct the user to a replica Firefox Screenshots page that could be used for phishing. This vulnerability affects Firefox < 127. | |
| CVE-2024-5688 | Hig | 8.1 | < 127.0.2-r0 | 127.0.2-r0 | Jun 11, 2024 | If a garbage collection was triggered at the right time, a use-after-free could have occurred during object transplant. This vulnerability affects Firefox < 127, Firefox ESR < 115.12, and Thunderbird < 115.12. | |
| CVE-2024-5687 | Med | 5.3 | < 127.0.2-r0 | 127.0.2-r0 | Jun 11, 2024 | If a specific sequence of actions is performed when opening a new tab, the triggering principal associated with the new tab may have been incorrect. The triggering principal is used to calculate many values, including the `Referer` and `Sec-*` headers, meaning there is the potent | |
| CVE-2024-0953 | Med | 6.1 | < 136.0.2-r0 | 136.0.2-r0 | Feb 5, 2024 | When a user scans a QR Code with the QR Code Scanner feature, the user is not prompted before being navigated to the page specified in the code. This may surprise the user and potentially direct them to unwanted content. This vulnerability affects Firefox for iOS < 129. | |
| CVE-2022-4066 | Low | 3.5 | < 136.0.2-r0 | 136.0.2-r0 | Nov 19, 2022 | A vulnerability was found in davidmoreno onion. It has been rated as problematic. Affected by this issue is the function onion_response_flush of the file src/onion/response.c of the component Log Handler. The manipulation leads to allocation of resources. The name of the patch is | |
| CVE-2007-5967 | Med | 6.5 | < 0 | 0 | May 17, 2021 | A flaw in Mozilla's embedded certificate code might allow web sites to install root certificates on devices without user approval. | |
| CVE-2019-7317 | Med | 5.3 | < 0 | 0 | Feb 4, 2019 | png_image_free in png.c in libpng 1.6.x before 1.6.37 has a use-after-free because png_image_free_function is called under png_safe_execute. | |
| CVE-2018-8024 | Med | 5.4 | < 136.0.2-r0 | 136.0.2-r0 | Jul 12, 2018 | In Apache Spark 2.1.0 to 2.1.2, 2.2.0 to 2.2.1, and 2.3.0, it's possible for a malicious user to construct a URL pointing to a Spark cluster's UI's job and stage info pages, and if a user can be tricked into accessing the URL, can be used to cause script to execute and expose inf | |
| CVE-2018-10229 | Med | 4.8 | < 0 | 0 | May 4, 2018 | A hardware vulnerability in GPU memory modules allows attackers to accelerate micro-architectural attacks through the use of the JavaScript WebGL API. | |
| CVE-2016-7153 | Med | 5.3 | < 144.0.2-r0 | 144.0.2-r0 | Sep 6, 2016 | The HTTP/2 protocol does not consider the role of the TCP congestion window in providing information about content length, which makes it easier for remote attackers to obtain cleartext data by leveraging a web-browser configuration in which third-party cookies are sent, aka a "H |
- affected < 127.0.2-r0fixed 127.0.2-r0
In violation of spec, cookie prefixes such as `__Secure` were being ignored if they were not correctly capitalized - by spec they should be checked with a case-insensitive comparison. This could have resulted in the browser not correctly honoring the behaviors specified by the pr
- affected < 127.0.2-r0fixed 127.0.2-r0
By manipulating the fullscreen feature while opening a data-list, an attacker could have overlaid a text box over the address bar. This could have led to user confusion and possible spoofing attacks. This vulnerability affects Firefox < 127.
- affected < 127.0.2-r0fixed 127.0.2-r0
A website was able to detect when a user took a screenshot of a page using the built-in Screenshot functionality in Firefox. This vulnerability affects Firefox < 127.
- affected < 127.0.2-r0fixed 127.0.2-r0
By manipulating the text in an `<input>` tag, an attacker could have caused corrupt memory leading to a potentially exploitable crash. This vulnerability affects Firefox < 127, Firefox ESR < 115.12, and Thunderbird < 115.12.
- affected < 127.0.2-r0fixed 127.0.2-r0
If an out-of-memory condition occurs at a specific point using allocations in the probabilistic heap checker, an assertion could have been triggered, and in rarer situations, memory corruption could have occurred. This vulnerability affects Firefox < 127.
- affected < 127.0.2-r0fixed 127.0.2-r0
An attacker could have caused a use-after-free in the JavaScript engine to read memory in the JavaScript string section of the heap. This vulnerability affects Firefox < 127.
- affected < 127.0.2-r0fixed 127.0.2-r0
Offscreen Canvas did not properly track cross-origin tainting, which could be used to access image data from another site in violation of same-origin policy. This vulnerability affects Firefox < 127, Firefox ESR < 115.12, and Thunderbird < 115.12.
- affected < 127.0.2-r0fixed 127.0.2-r0
On Windows 10, when using the 'Save As' functionality, an attacker could have tricked the browser into saving the file with a disallowed extension such as `.url` by including an invalid character in the extension. *Note:* This issue only affected Windows operating systems. Other
- affected < 127.0.2-r0fixed 127.0.2-r0
By tricking the browser with a `X-Frame-Options` header, a sandboxed iframe could have presented a button that, if clicked by a user, would bypass restrictions to open a new window. This vulnerability affects Firefox < 127, Firefox ESR < 115.12, and Thunderbird < 115.12.
- affected < 127.0.2-r0fixed 127.0.2-r0
By monitoring the time certain operations take, an attacker could have guessed which external protocol handlers were functional on a user's system. This vulnerability affects Firefox < 127, Firefox ESR < 115.12, and Thunderbird < 115.12.
- affected < 127.0.2-r0fixed 127.0.2-r0
In addition to detecting when a user was taking a screenshot (XXX), a website was able to overlay the 'My Shots' button that appeared, and direct the user to a replica Firefox Screenshots page that could be used for phishing. This vulnerability affects Firefox < 127.
- affected < 127.0.2-r0fixed 127.0.2-r0
If a garbage collection was triggered at the right time, a use-after-free could have occurred during object transplant. This vulnerability affects Firefox < 127, Firefox ESR < 115.12, and Thunderbird < 115.12.
- affected < 127.0.2-r0fixed 127.0.2-r0
If a specific sequence of actions is performed when opening a new tab, the triggering principal associated with the new tab may have been incorrect. The triggering principal is used to calculate many values, including the `Referer` and `Sec-*` headers, meaning there is the potent
- affected < 136.0.2-r0fixed 136.0.2-r0
When a user scans a QR Code with the QR Code Scanner feature, the user is not prompted before being navigated to the page specified in the code. This may surprise the user and potentially direct them to unwanted content. This vulnerability affects Firefox for iOS < 129.
- affected < 136.0.2-r0fixed 136.0.2-r0
A vulnerability was found in davidmoreno onion. It has been rated as problematic. Affected by this issue is the function onion_response_flush of the file src/onion/response.c of the component Log Handler. The manipulation leads to allocation of resources. The name of the patch is
- affected < 0fixed 0
A flaw in Mozilla's embedded certificate code might allow web sites to install root certificates on devices without user approval.
- affected < 0fixed 0
png_image_free in png.c in libpng 1.6.x before 1.6.37 has a use-after-free because png_image_free_function is called under png_safe_execute.
- affected < 136.0.2-r0fixed 136.0.2-r0
In Apache Spark 2.1.0 to 2.1.2, 2.2.0 to 2.2.1, and 2.3.0, it's possible for a malicious user to construct a URL pointing to a Spark cluster's UI's job and stage info pages, and if a user can be tricked into accessing the URL, can be used to cause script to execute and expose inf
- affected < 0fixed 0
A hardware vulnerability in GPU memory modules allows attackers to accelerate micro-architectural attacks through the use of the JavaScript WebGL API.
- affected < 144.0.2-r0fixed 144.0.2-r0
The HTTP/2 protocol does not consider the role of the TCP congestion window in providing information about content length, which makes it easier for remote attackers to obtain cleartext data by leveraging a web-browser configuration in which third-party cookies are sent, aka a "H
Page 33 of 35