Vulnerabilities
Vulnerable Software
Security Vulnerabilities - CVEs Published In 2024
An attacker could cause a select dropdown to be shown over another tab; this could have led to user confusion and possible spoofing attacks. This vulnerability affects Firefox < 133, Firefox ESR < 128.5, Thunderbird < 133, and Thunderbird < 128.5.
CVSS Score
4.3
EPSS Score
0.005
Published
2024-11-26
The executable file warning was not presented when downloading .library-ms files. *Note: This issue only affected Windows operating systems. Other operating systems are unaffected.* This vulnerability affects Firefox < 133, Firefox ESR < 128.5, Thunderbird < 133, and Thunderbird < 128.5.
CVSS Score
9.8
EPSS Score
0.008
Published
2024-11-26
Enhanced Tracking Protection's Strict mode may have inadvertently allowed a CSP `frame-src` bypass and DOM-based XSS through the Google SafeFrame shim in the Web Compatibility extension. This issue could have exposed users to malicious frames masquerading as legitimate content. This vulnerability affects Firefox < 133, Firefox ESR < 128.5, Firefox ESR < 115.18, Thunderbird < 133, Thunderbird < 128.5, and Thunderbird < 115.18.
CVSS Score
6.1
EPSS Score
0.005
Published
2024-11-26
QSEE will randomly experience a fatal error during execution due to speculative instruction fetches from device memory. Device memory is not valid executable memory.
CVSS Score
8.4
EPSS Score
0.001
Published
2024-11-26
Information disclosure due to uninitialized variable.
CVSS Score
8.4
EPSS Score
0.001
Published
2024-11-26
Information disclosure possible while audio playback.
CVSS Score
8.4
EPSS Score
0.001
Published
2024-11-26
Crafted Binder Request Causes Heap UAF in MediaServer
CVSS Score
7.8
EPSS Score
0.001
Published
2024-11-26
An unsigned integer underflow vulnerability in IPA driver result into a buffer over-read while reading NAT entry using debugfs command 'cat /sys/kernel/debug/ipa/ip4_nat'
CVSS Score
8.4
EPSS Score
0.001
Published
2024-11-26
Out-of-bounds Read vulnerability in Apache NimBLE. Missing proper validation of HCI Number Of Completed Packets could lead to out-of-bound access when parsing HCI event and invalid read from HCI transport memory. This issue requires broken or bogus Bluetooth controller and thus severity is considered low. This issue affects Apache NimBLE: through 1.7.0. Users are recommended to upgrade to version 1.8.0, which fixes the issue.
CVSS Score
7.5
EPSS Score
0.012
Published
2024-11-26
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in Apache NimBLE. Specially crafted MESH message could result in memory corruption when non-default build configuration is used. This issue affects Apache NimBLE: through 1.7.0. Users are recommended to upgrade to version 1.8.0, which fixes the issue.
CVSS Score
6.3
EPSS Score
0.007
Published
2024-11-26


Contact Us

Shodan ® - All rights reserved