![]() |
Home ▼ Bookkeeping
Online ▼ Security
Audits ▼
Managed
DNS ▼
About
Order
FAQ
Acceptable Use Policy
Dynamic DNS Clients
Configure Domains Dyanmic DNS Update Password Network
Monitor ▼
Enterprise Package
Advanced Package
Standard Package
Free Trial
FAQ
Price/Feature Summary
Order/Renew
Examples
Configure/Status Alert Profiles | ||
Test ID: | 1.3.6.1.4.1.25623.1.2.1.2024.25 |
Category: | General |
Title: | Mozilla Firefox Security Advisory (MFSA2024-25) - Linux |
Summary: | This host is missing a security update for Mozilla Firefox. |
Description: | Summary: This host is missing a security update for Mozilla Firefox. Vulnerability Insight: CVE-2024-5688: Use-after-free in JavaScript object transplant If a garbage collection was triggered at the right time, a use-after-free could have occurred during object transplant. CVE-2024-5689: User confusion and possible phishing vector via Firefox Screenshots In addition to detecting when a user was taking a screenshot (XXX), a website was able to overlay the 'My Shots' button that appeared, and direct the user to a replica Firefox Screenshots page that could be used for phishing. CVE-2024-5690: External protocol handlers leaked by timing attack By monitoring the time certain operations take, an attacker could have guessed which external protocol handlers were functional on a user's system. CVE-2024-5691: Sandboxed iframes were able to bypass sandbox restrictions to open a new window By tricking the browser with a X-Frame-Options header, a sandboxed iframe could have presented a button that, if clicked by a user, would bypass restrictions to open a new window. CVE-2024-5693: Cross-Origin Image leak via Offscreen Canvas Offscreen Canvas did not properly track cross-origin tainting, which could be used to access image data from another site in violation of same-origin policy. CVE-2024-5694: Use-after-free in JavaScript Strings An attacker could have caused a use-after-free in the JavaScript engine to read memory in the JavaScript string section of the heap. CVE-2024-5695: Memory Corruption using allocation using out-of-memory conditions If an out-of-memory condition occurs at a specific point using allocations in the probabilistic heap checker, an assertion could have been triggered, and in rarer situations, memory corruption could have occurred. CVE-2024-5696: Memory Corruption in Text Fragments By manipulating the text in an tag, an attacker could have caused corrupt memory leading to a potentially exploitable crash. CVE-2024-5697: Website was able to detect when Firefox was taking a screenshot of them A website was able to ... [Please see the references for more information on the vulnerabilities] Affected Software/OS: Firefox version(s) below 127. Solution: The vendor has released an update. Please see the reference(s) for more information. CVSS Score: 10.0 CVSS Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C |
Cross-Ref: |
Common Vulnerability Exposure (CVE) ID: CVE-2024-5688 https://bugzilla.mozilla.org/show_bug.cgi?id=1895086 https://lists.debian.org/debian-lts-announce/2024/06/msg00000.html https://www.mozilla.org/security/advisories/mfsa2024-25/ https://www.mozilla.org/security/advisories/mfsa2024-26/ https://www.mozilla.org/security/advisories/mfsa2024-28/ https://lists.debian.org/debian-lts-announce/2024/06/msg00010.html Common Vulnerability Exposure (CVE) ID: CVE-2024-5689 https://bugzilla.mozilla.org/show_bug.cgi?id=1389707 Common Vulnerability Exposure (CVE) ID: CVE-2024-5690 https://bugzilla.mozilla.org/show_bug.cgi?id=1883693 Common Vulnerability Exposure (CVE) ID: CVE-2024-5691 https://bugzilla.mozilla.org/show_bug.cgi?id=1888695 Common Vulnerability Exposure (CVE) ID: CVE-2024-5693 https://bugzilla.mozilla.org/show_bug.cgi?id=1891319 Common Vulnerability Exposure (CVE) ID: CVE-2024-5694 https://bugzilla.mozilla.org/show_bug.cgi?id=1895055 Common Vulnerability Exposure (CVE) ID: CVE-2024-5695 https://bugzilla.mozilla.org/show_bug.cgi?id=1895579 Common Vulnerability Exposure (CVE) ID: CVE-2024-5696 https://bugzilla.mozilla.org/show_bug.cgi?id=1896555 Common Vulnerability Exposure (CVE) ID: CVE-2024-5697 https://bugzilla.mozilla.org/show_bug.cgi?id=1414937 Common Vulnerability Exposure (CVE) ID: CVE-2024-5698 https://bugzilla.mozilla.org/show_bug.cgi?id=1828259 Common Vulnerability Exposure (CVE) ID: CVE-2024-5699 https://bugzilla.mozilla.org/show_bug.cgi?id=1891349 Common Vulnerability Exposure (CVE) ID: CVE-2024-5700 Memory safety bugs fixed in Firefox 127, Firefox ESR 115.12, and Thunderbird 115.12 https://bugzilla.mozilla.org/buglist.cgi?bug_id=1862809%2C1889355%2C1893388%2C1895123 Common Vulnerability Exposure (CVE) ID: CVE-2024-5701 Memory safety bugs fixed in Firefox 127 https://bugzilla.mozilla.org/buglist.cgi?bug_id=1890909%2C1891422%2C1893915%2C1894047%2C1896024 |
Copyright | Copyright (C) 2024 Greenbone AG |
This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit. To run a free test of this vulnerability against your system, register below. |