Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.2.1.2024.25
Category:General
Title:Mozilla Firefox Security Advisory (MFSA2024-25) - Linux
Summary:This host is missing a security update for Mozilla Firefox.
Description:Summary:
This host is missing a security update for Mozilla Firefox.

Vulnerability Insight:
CVE-2024-5688: Use-after-free in JavaScript object transplant
If a garbage collection was triggered at the right time, a use-after-free could have occurred during object transplant.

CVE-2024-5689: User confusion and possible phishing vector via Firefox Screenshots
In addition to detecting when a user was taking a screenshot (XXX), a website was able to overlay the 'My Shots' button that appeared, and direct the user to a replica Firefox Screenshots page that could be used for phishing.

CVE-2024-5690: External protocol handlers leaked by timing attack
By monitoring the time certain operations take, an attacker could have guessed which external protocol handlers were functional on a user's system.

CVE-2024-5691: Sandboxed iframes were able to bypass sandbox restrictions to open a new window
By tricking the browser with a X-Frame-Options header, a sandboxed iframe could have presented a button that, if clicked by a user, would bypass restrictions to open a new window.

CVE-2024-5693: Cross-Origin Image leak via Offscreen Canvas
Offscreen Canvas did not properly track cross-origin tainting, which could be used to access image data from another site in violation of same-origin policy.

CVE-2024-5694: Use-after-free in JavaScript Strings
An attacker could have caused a use-after-free in the JavaScript engine to read memory in the JavaScript string section of the heap.

CVE-2024-5695: Memory Corruption using allocation using out-of-memory conditions
If an out-of-memory condition occurs at a specific point using allocations in the probabilistic heap checker, an assertion could have been triggered, and in rarer situations, memory corruption could have occurred.

CVE-2024-5696: Memory Corruption in Text Fragments
By manipulating the text in an tag, an attacker could have caused corrupt memory leading to a potentially exploitable crash.

CVE-2024-5697: Website was able to detect when Firefox was taking a screenshot of them
A website was able to ... [Please see the references for more information on the vulnerabilities]

Affected Software/OS:
Firefox version(s) below 127.

Solution:
The vendor has released an update. Please see the reference(s) for more information.

CVSS Score:
10.0

CVSS Vector:
AV:N/AC:L/Au:N/C:C/I:C/A:C

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2024-5688
https://bugzilla.mozilla.org/show_bug.cgi?id=1895086
https://lists.debian.org/debian-lts-announce/2024/06/msg00000.html
https://www.mozilla.org/security/advisories/mfsa2024-25/
https://www.mozilla.org/security/advisories/mfsa2024-26/
https://www.mozilla.org/security/advisories/mfsa2024-28/
https://lists.debian.org/debian-lts-announce/2024/06/msg00010.html
Common Vulnerability Exposure (CVE) ID: CVE-2024-5689
https://bugzilla.mozilla.org/show_bug.cgi?id=1389707
Common Vulnerability Exposure (CVE) ID: CVE-2024-5690
https://bugzilla.mozilla.org/show_bug.cgi?id=1883693
Common Vulnerability Exposure (CVE) ID: CVE-2024-5691
https://bugzilla.mozilla.org/show_bug.cgi?id=1888695
Common Vulnerability Exposure (CVE) ID: CVE-2024-5693
https://bugzilla.mozilla.org/show_bug.cgi?id=1891319
Common Vulnerability Exposure (CVE) ID: CVE-2024-5694
https://bugzilla.mozilla.org/show_bug.cgi?id=1895055
Common Vulnerability Exposure (CVE) ID: CVE-2024-5695
https://bugzilla.mozilla.org/show_bug.cgi?id=1895579
Common Vulnerability Exposure (CVE) ID: CVE-2024-5696
https://bugzilla.mozilla.org/show_bug.cgi?id=1896555
Common Vulnerability Exposure (CVE) ID: CVE-2024-5697
https://bugzilla.mozilla.org/show_bug.cgi?id=1414937
Common Vulnerability Exposure (CVE) ID: CVE-2024-5698
https://bugzilla.mozilla.org/show_bug.cgi?id=1828259
Common Vulnerability Exposure (CVE) ID: CVE-2024-5699
https://bugzilla.mozilla.org/show_bug.cgi?id=1891349
Common Vulnerability Exposure (CVE) ID: CVE-2024-5700
Memory safety bugs fixed in Firefox 127, Firefox ESR 115.12, and Thunderbird 115.12
https://bugzilla.mozilla.org/buglist.cgi?bug_id=1862809%2C1889355%2C1893388%2C1895123
Common Vulnerability Exposure (CVE) ID: CVE-2024-5701
Memory safety bugs fixed in Firefox 127
https://bugzilla.mozilla.org/buglist.cgi?bug_id=1890909%2C1891422%2C1893915%2C1894047%2C1896024
CopyrightCopyright (C) 2024 Greenbone AG

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.