Latest CVE Feed
-
8.8
HIGHCVE-2024-11697
When handling keypress events, an attacker may have been able to trick a user into bypassing the "Open Executable File?" confirmation dialog. This could have led to malicious code execution. This vulnerability affects Firefox < 133, Firefox ESR < 128.5, T... Read more
- Published: Nov. 26, 2024
- Modified: Apr. 03, 2025
-
5.4
MEDIUMCVE-2024-11696
The application failed to account for exceptions thrown by the `loadManifestFromFile` method during add-on signature verification. This flaw, triggered by an invalid or unsupported extension manifest, could have caused runtime errors that disrupted the si... Read more
- Published: Nov. 26, 2024
- Modified: Jun. 24, 2025
-
5.4
MEDIUMCVE-2024-11695
A crafted URL containing Arabic script and whitespace characters could have hidden the true origin of the page, resulting in a potential spoofing attack. This vulnerability affects Firefox < 133, Firefox ESR < 128.5, Thunderbird < 133, and Thunderbird < 1... Read more
- Published: Nov. 26, 2024
- Modified: Apr. 03, 2025
-
6.1
MEDIUMCVE-2024-11694
Enhanced Tracking Protection's Strict mode may have inadvertently allowed a CSP `frame-src` bypass and DOM-based XSS through the Google SafeFrame shim in the Web Compatibility extension. This issue could have exposed users to malicious frames masquerading... Read more
- Published: Nov. 26, 2024
- Modified: Jun. 24, 2025
-
9.8
CRITICALCVE-2024-11693
The executable file warning was not presented when downloading .library-ms files. *Note: This issue only affected Windows operating systems. Other operating systems are unaffected.* This vulnerability affects Firefox < 133, Firefox ESR < 128.5, Thunderb... Read more
- Published: Nov. 26, 2024
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2024-11692
An attacker could cause a select dropdown to be shown over another tab; this could have led to user confusion and possible spoofing attacks. This vulnerability affects Firefox < 133, Firefox ESR < 128.5, Thunderbird < 133, and Thunderbird < 128.5.... Read more
- Published: Nov. 26, 2024
- Modified: Apr. 03, 2025
-
8.8
HIGHCVE-2024-11691
Certain WebGL operations on Apple silicon M series devices could have lead to an out-of-bounds write and memory corruption due to a flaw in Apple's GPU driver. *This bug only affected the application on Apple M series hardware. Other platforms were unaf... Read more
Affected Products : firefox firefox_esr thunderbird m1 m1_max m1_pro m1_ultra m2 m2_max m2_pro +8 more products- Published: Nov. 26, 2024
- Modified: Jun. 24, 2025
-
8.4
HIGHCVE-2018-5852
An unsigned integer underflow vulnerability in IPA driver result into a buffer over-read while reading NAT entry using debugfs command 'cat /sys/kernel/debug/ipa/ip4_nat'... Read more
Affected Products : sd_450_firmware sd_625_firmware sd_820_firmware sd_820a_firmware sd_835_firmware mdm9650_firmware msm8909w_firmware mdm9206_firmware mdm9607_firmware mdm9640_firmware +36 more products- Published: Nov. 26, 2024
- Modified: Jan. 09, 2025
-
7.8
HIGHCVE-2018-11816
Crafted Binder Request Causes Heap UAF in MediaServer... Read more
Affected Products : aqt1000_firmware sd660_firmware sd670_firmware sd835_firmware apq8052_firmware apq8056_firmware apq8076_firmware apq8017_firmware sd820_firmware sd821_firmware +18 more products- Published: Nov. 26, 2024
- Modified: Feb. 06, 2025
-
8.4
HIGHCVE-2017-18307
Information disclosure possible while audio playback.... Read more
Affected Products : sd_450_firmware sd_625_firmware sd_820_firmware sd_820a_firmware sd_835_firmware sd_845_firmware sd_850_firmware sd_625 sd_820 sd_835 +4 more products- Published: Nov. 26, 2024
- Modified: Jan. 09, 2025
-
8.4
HIGHCVE-2017-18306
Information disclosure due to uninitialized variable.... Read more
Affected Products : sd_450_firmware sd_625_firmware sd_820_firmware sd_820a_firmware sd_835_firmware sd_845_firmware sd_850_firmware sd_625 sd_820 sd_835 +4 more products- Published: Nov. 26, 2024
- Modified: Jan. 09, 2025
-
8.4
HIGHCVE-2016-10408
QSEE will randomly experience a fatal error during execution due to speculative instruction fetches from device memory. Device memory is not valid executable memory.... Read more
- Published: Nov. 26, 2024
- Modified: Jan. 09, 2025
-
7.5
HIGHCVE-2024-51569
Out-of-bounds Read vulnerability in Apache NimBLE. Missing proper validation of HCI Number Of Completed Packets could lead to out-of-bound access when parsing HCI event and invalid read from HCI transport memory. This issue requires broken or bogus Bluet... Read more
Affected Products : nimble- Published: Nov. 26, 2024
- Modified: Jul. 08, 2025
-
5.0
MEDIUMCVE-2024-47250
Out-of-bounds Read vulnerability in Apache NimBLE. Missing proper validation of HCI advertising report could lead to out-of-bound access when parsing HCI event and thus bogus GAP 'device found' events being sent. This issue requires broken or bogus Bluet... Read more
Affected Products : nimble- Published: Nov. 26, 2024
- Modified: Jul. 08, 2025
-
5.0
MEDIUMCVE-2024-47249
Improper Validation of Array Index vulnerability in Apache NimBLE. Lack of input validation for HCI events from controller could result in out-of-bound memory corruption and crash. This issue requires broken or bogus Bluetooth controller and thus severit... Read more
Affected Products : nimble- Published: Nov. 26, 2024
- Modified: Jul. 08, 2025
-
6.3
MEDIUMCVE-2024-47248
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in Apache NimBLE. Specially crafted MESH message could result in memory corruption when non-default build configuration is used. This issue affects Apache NimBLE: throug... Read more
Affected Products : nimble- Published: Nov. 26, 2024
- Modified: Jul. 08, 2025
-
6.5
MEDIUMCVE-2024-38834
VMware Aria Operations contains a stored cross-site scripting vulnerability. A malicious actor with editing access to cloud provider might be able to inject malicious script leading to stored cross-site scripting in the product VMware Aria Operations.... Read more
- Published: Nov. 26, 2024
- Modified: May. 14, 2025
-
6.8
MEDIUMCVE-2024-38833
VMware Aria Operations contains a stored cross-site scripting vulnerability. A malicious actor with editing access to email templates might inject malicious script leading to stored cross-site scripting in the product VMware Aria Operations.... Read more
- Published: Nov. 26, 2024
- Modified: May. 14, 2025
-
7.1
HIGHCVE-2024-38832
VMware Aria Operations contains a stored cross-site scripting vulnerability. A malicious actor with editing access to views may be able to inject malicious script leading to stored cross-site scripting in the product VMware Aria Operations.... Read more
- Published: Nov. 26, 2024
- Modified: May. 14, 2025
-
7.8
HIGHCVE-2024-38831
VMware Aria Operations contains a local privilege escalation vulnerability. A malicious actor with local administrative privileges can insert malicious commands into the properties file to escalate privileges to a root user on the appliance running VMwa... Read more
- Published: Nov. 26, 2024
- Modified: May. 14, 2025