Latest CVE Feed
-
8.8
HIGHCVE-2021-23962
Incorrect use of the '<RowCountChanged>' method could have led to a user-after-poison and a potentially exploitable crash. This vulnerability affects Firefox < 85.... Read more
Affected Products : firefox- Published: Feb. 26, 2021
- Modified: Nov. 21, 2024
-
7.4
HIGHCVE-2021-23961
Further techniques that built on the slipstream research combined with a malicious webpage could have exposed both an internal network's hosts as well as services running on the user's local machine. This vulnerability affects Firefox < 85.... Read more
- Published: Feb. 26, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-23960
Performing garbage collection on re-declared JavaScript variables resulted in a user-after-poison, and a potentially exploitable crash. This vulnerability affects Firefox < 85, Thunderbird < 78.7, and Firefox ESR < 78.7.... Read more
- Published: Feb. 26, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-23959
An XSS bug in internal error pages could have led to various spoofing attacks, including other error pages and the address bar. Note: This issue only affected Firefox for Android. Other operating systems are unaffected. This vulnerability affects Firefox ... Read more
Affected Products : firefox- Published: Feb. 26, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-23958
The browser could have been confused into transferring a screen sharing state into another tab, which would leak unintended information. This vulnerability affects Firefox < 85.... Read more
Affected Products : firefox- Published: Feb. 26, 2021
- Modified: Nov. 21, 2024
-
7.4
HIGHCVE-2021-23957
Navigations through the Android-specific `intent` URL scheme could have been misused to escape iframe sandbox. Note: This issue only affected Firefox for Android. Other operating systems are unaffected. This vulnerability affects Firefox < 85.... Read more
Affected Products : firefox- Published: Feb. 26, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-23956
An ambiguous file picker design could have confused users who intended to select and upload a single file into uploading a whole directory. This was addressed by adding a new prompt. This vulnerability affects Firefox < 85.... Read more
Affected Products : firefox- Published: Feb. 26, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-23955
The browser could have been confused into transferring a pointer lock state into another tab, which could have lead to clickjacking attacks. This vulnerability affects Firefox < 85.... Read more
Affected Products : firefox- Published: Feb. 26, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-23954
Using the new logical assignment operators in a JavaScript switch statement could have caused a type confusion, leading to a memory corruption and a potentially exploitable crash. This vulnerability affects Firefox < 85, Thunderbird < 78.7, and Firefox ES... Read more
- Published: Feb. 26, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-23953
If a user clicked into a specifically crafted PDF, the PDF reader could be confused into leaking cross-origin information, when said information is served as chunked data. This vulnerability affects Firefox < 85, Thunderbird < 78.7, and Firefox ESR < 78.7... Read more
- Published: Feb. 26, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-23937
A DNS proxy and possible amplification attack vulnerability in WebClientInfo of Apache Wicket allows an attacker to trigger arbitrary DNS lookups from the server when the X-Forwarded-For header is not properly sanitized. This DNS lookup can be engineered ... Read more
Affected Products : wicket- Published: May. 25, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-23936
OX App Suite through 7.10.4 allows XSS via the subject of a task.... Read more
Affected Products : open-xchange_appsuite- Published: Jan. 12, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-23935
OX App Suite through 7.10.4 allows XSS via an appointment in which the location contains JavaScript code.... Read more
Affected Products : open-xchange_appsuite- Published: Jan. 12, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-23934
OX App Suite through 7.10.4 allows XSS via a contact whose name contains JavaScript code.... Read more
Affected Products : open-xchange_appsuite- Published: Jan. 12, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-23933
OX App Suite through 7.10.4 allows XSS via JavaScript in a Note referenced by a mail:// URL.... Read more
Affected Products : open-xchange_appsuite- Published: Jan. 12, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-23932
OX App Suite through 7.10.4 allows XSS via an inline image with a crafted filename.... Read more
Affected Products : open-xchange_appsuite- Published: Jan. 12, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-23931
OX App Suite through 7.10.4 allows XSS via an inline binary file.... Read more
Affected Products : open-xchange_appsuite- Published: Jan. 12, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-23930
OX App Suite through 7.10.4 allows XSS via use of the conversion API for a distributedFile.... Read more
Affected Products : open-xchange_appsuite- Published: Jan. 12, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-23929
OX App Suite through 7.10.4 allows XSS via a crafted Content-Disposition header in an uploaded HTML document to an ajax/share/<share-token>?delivery=view URI.... Read more
Affected Products : open-xchange_appsuite- Published: Jan. 12, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-23928
OX App Suite through 7.10.3 allows XSS via the ajax/apps/manifests query string.... Read more
Affected Products : open-xchange_appsuite- Published: Jan. 12, 2021
- Modified: Nov. 21, 2024