Threats Tagged 'cve-2024-4767'
View all threats tagged with 'cve-2024-4767'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cve-2024-4767'
Click on any threat for detailed analysis and mitigation recommendations
0 This update for webkit2gtk3 fixes the following issues: - CVE-2024-4367: missing type check when handling fonts in PDF.js can allow arbitrary JavaScript execution (bsc#1271638). - CVE-2026-39872: maliciously crafted web content can lead to an unexpected process crash (bsc#1271638). - CVE-2026-43663: maliciously crafted web content can lead to an unexpected process crash (bsc#1271638). - CVE-2026-43676: out-of-bounds access when processing web content can lead to an unexpected Safari crash (bsc#1271638). - CVE-2026-43699: use-after-free issue when processing web content can lead to an unexpected process crash (bsc#1271638). - CVE-2026-43701: malicious website can process restricted web content outside the sandbox (bsc#1271638). - CVE-2026-43705: type confusion issue when processing web content can lead to memory corruption (bsc#1271638). - CVE-2026-43707: memory corruption issue when processing web content can lead to an unexpected process crash (bsc#1271638). - CVE-2026-43712: maliciously crafted web content can lead to an unexpected process crash (bsc#1271638). - CVE-2026-43713: visiting a website can leak sensitive data due to a permissions issue (bsc#1271638). - CVE-2026-43715: use-after-free issue when processing web content can lead to memory corruption (bsc#1271638). - CVE-2026-43716: maliciously crafted web content can lead to an unexpected Safari crash (bsc#1271638). - CVE-2026-43720: use-after-free issue when processing web content can lead to an unexpected Safari crash (bsc#1271638). - CVE-2026-43721: malicious website can silently hijack clipboard data (bsc#1271638). - CVE-2026-43725: unvalidated input can allow a malicious website to process restricted web content outside the sandbox (bsc#1271638). - CVE-2026-43726: use-after-free issue when processing web content can lead to an unexpected process crash (bsc#1271638). - CVE-2026-43727: use-after-free issue when processing web content can lead to an unexpected Safari crash (bsc#1271638). - CVE-2026-43731: use-after-free issue when processing web content can lead to memory corruption (bsc#1271638). - CVE-2026-43732: path handling issue when processing web content can disclose sensitive user information (bsc#1271638). - CVE-2026-43734: use-after-free issue when processing web content can lead to an unexpected process crash (bsc#1271638). - CVE-2026-43740: maliciously crafted web content can result in the disclosure of process memory (bsc#1271638). - CVE-2026-43742: use-after-free issue when processing web content can lead to an unexpected process crash (bsc#1271638). - CVE-2026-43745: out-of-bounds write issue when processing web content can lead to an unexpected Safari crash (bsc#1271638). Changes for webkit2gtk3: - Update to version 2.52.5: * Fire scrollend event for instant programmatic scrolls. * Increase network idle connection timeout to 115 seconds. * Add User-Agent quirk for HBO Max. * Fix the build with system malloc. Join the discussion | GCVE Database | 08/01/2026, 12:18:12 UTC Added: 06/23/2026, 15:50:47 UTC |
0 This update for webkit2gtk3 fixes the following issues: - CVE-2024-4367: missing type check when handling fonts in PDF.js can allow arbitrary JavaScript execution (bsc#1271638). - CVE-2026-39872: maliciously crafted web content can lead to an unexpected process crash (bsc#1271638). - CVE-2026-43663: maliciously crafted web content can lead to an unexpected process crash (bsc#1271638). - CVE-2026-43676: out-of-bounds access when processing web content can lead to an unexpected Safari crash (bsc#1271638). - CVE-2026-43699: use-after-free issue when processing web content can lead to an unexpected process crash (bsc#1271638). - CVE-2026-43701: malicious website can process restricted web content outside the sandbox (bsc#1271638). - CVE-2026-43705: type confusion issue when processing web content can lead to memory corruption (bsc#1271638). - CVE-2026-43707: memory corruption issue when processing web content can lead to an unexpected process crash (bsc#1271638). - CVE-2026-43712: maliciously crafted web content can lead to an unexpected process crash (bsc#1271638). - CVE-2026-43713: visiting a website can leak sensitive data due to a permissions issue (bsc#1271638). - CVE-2026-43715: use-after-free issue when processing web content can lead to memory corruption (bsc#1271638). - CVE-2026-43716: maliciously crafted web content can lead to an unexpected Safari crash (bsc#1271638). - CVE-2026-43720: use-after-free issue when processing web content can lead to an unexpected Safari crash (bsc#1271638). - CVE-2026-43721: malicious website can silently hijack clipboard data (bsc#1271638). - CVE-2026-43725: unvalidated input can allow a malicious website to process restricted web content outside the sandbox (bsc#1271638). - CVE-2026-43726: use-after-free issue when processing web content can lead to an unexpected process crash (bsc#1271638). - CVE-2026-43727: use-after-free issue when processing web content can lead to an unexpected Safari crash (bsc#1271638). - CVE-2026-43731: use-after-free issue when processing web content can lead to memory corruption (bsc#1271638). - CVE-2026-43732: path handling issue when processing web content can disclose sensitive user information (bsc#1271638). - CVE-2026-43734: use-after-free issue when processing web content can lead to an unexpected process crash (bsc#1271638). - CVE-2026-43740: maliciously crafted web content can result in the disclosure of process memory (bsc#1271638). - CVE-2026-43742: use-after-free issue when processing web content can lead to an unexpected process crash (bsc#1271638). - CVE-2026-43745: out-of-bounds write issue when processing web content can lead to an unexpected Safari crash (bsc#1271638). Changes for webkit2gtk3: - Update to version 2.52.5: * Fire scrollend event for instant programmatic scrolls. * Increase network idle connection timeout to 115 seconds. * Add User-Agent quirk for HBO Max. * Fix the build with system malloc. Join the discussion | GCVE Database | 08/01/2026, 12:18:12 UTC Added: 06/23/2026, 15:50:46 UTC |
0 Mozilla Firefox is an open-source web browser, designed for standards compliance, performance, and portability. This update upgrades Firefox to version 115.11.0 ESR. Security Fix(es): * firefox: Arbitrary JavaScript execution in PDF.js (CVE-2024-4367) * firefox: IndexedDB files retained in private browsing mode (CVE-2024-4767) * firefox: Potential permissions request bypass via clickjacking (CVE-2024-4768) * firefox: Cross-origin responses could be distinguished between script and non-script content-types (CVE-2024-4769) * firefox: Use-after-free could occur when printing to PDF (CVE-2024-4770) * firefox: Memory safety bugs fixed in Firefox 126, Firefox ESR 115.11, and Thunderbird 115.11 (CVE-2024-4777) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Join the discussion | GCVE Database | 06/10/2024, 19:39:38 UTC Added: 06/23/2026, 15:50:46 UTC |
0 Mozilla Thunderbird is a standalone mail and newsgroup client. This update upgrades Thunderbird to version 115.11.0. Security Fix(es): * Mozilla: Arbitrary JavaScript execution in PDF.js (CVE-2024-4367) * Mozilla: IndexedDB files retained in private browsing mode (CVE-2024-4767) * Mozilla: Potential permissions request bypass via clickjacking (CVE-2024-4768) * Mozilla: Cross-origin responses could be distinguished between script and non-script content-types (CVE-2024-4769) * Mozilla: Use-after-free could occur when printing to PDF (CVE-2024-4770) * Mozilla: Memory safety bugs fixed in Firefox 126, Firefox ESR 115.11, and Thunderbird 115.11 (CVE-2024-4777) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Join the discussion | GCVE Database | 05/23/2024, 12:09:34 UTC Added: 06/23/2026, 15:50:47 UTC |
0 Mozilla Thunderbird is a standalone mail and newsgroup client. This update upgrades Thunderbird to version 115.11.0. Security Fix(es): * firefox: Arbitrary JavaScript execution in PDF.js (CVE-2024-4367) * firefox: IndexedDB files retained in private browsing mode (CVE-2024-4767) * firefox: Potential permissions request bypass via clickjacking (CVE-2024-4768) * firefox: Cross-origin responses could be distinguished between script and non-script content-types (CVE-2024-4769) * firefox: Use-after-free could occur when printing to PDF (CVE-2024-4770) * firefox: Memory safety bugs fixed in Firefox 126, Firefox ESR 115.11, and Thunderbird 115.11 (CVE-2024-4777) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Join the discussion | GCVE Database | 05/20/2024, 08:07:12 UTC Added: 06/23/2026, 15:50:47 UTC |
0 Mozilla Thunderbird is a standalone mail and newsgroup client. This update upgrades Thunderbird to version 115.11.0. Security Fix(es): * firefox: Arbitrary JavaScript execution in PDF.js (CVE-2024-4367) * firefox: IndexedDB files retained in private browsing mode (CVE-2024-4767) * firefox: Potential permissions request bypass via clickjacking (CVE-2024-4768) * firefox: Cross-origin responses could be distinguished between script and non-script content-types (CVE-2024-4769) * firefox: Use-after-free could occur when printing to PDF (CVE-2024-4770) * firefox: Memory safety bugs fixed in Firefox 126, Firefox ESR 115.11, and Thunderbird 115.11 (CVE-2024-4777) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Join the discussion | GCVE Database | 05/20/2024, 07:56:42 UTC Added: 06/23/2026, 15:50:46 UTC |
0 Mozilla Thunderbird is a standalone mail and newsgroup client. This update upgrades Thunderbird to version 115.11.0. Security Fix(es): * firefox: Arbitrary JavaScript execution in PDF.js (CVE-2024-4367) * firefox: IndexedDB files retained in private browsing mode (CVE-2024-4767) * firefox: Potential permissions request bypass via clickjacking (CVE-2024-4768) * firefox: Cross-origin responses could be distinguished between script and non-script content-types (CVE-2024-4769) * firefox: Use-after-free could occur when printing to PDF (CVE-2024-4770) * firefox: Memory safety bugs fixed in Firefox 126, Firefox ESR 115.11, and Thunderbird 115.11 (CVE-2024-4777) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Join the discussion | GCVE Database | 05/20/2024, 06:01:57 UTC Added: 06/23/2026, 15:50:46 UTC |
0 Mozilla Thunderbird is a standalone mail and newsgroup client. This update upgrades Thunderbird to version 115.11.0. Security Fix(es): * firefox: Arbitrary JavaScript execution in PDF.js (CVE-2024-4367) * firefox: IndexedDB files retained in private browsing mode (CVE-2024-4767) * firefox: Potential permissions request bypass via clickjacking (CVE-2024-4768) * firefox: Cross-origin responses could be distinguished between script and non-script content-types (CVE-2024-4769) * firefox: Use-after-free could occur when printing to PDF (CVE-2024-4770) * firefox: Memory safety bugs fixed in Firefox 126, Firefox ESR 115.11, and Thunderbird 115.11 (CVE-2024-4777) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Join the discussion | GCVE Database | 05/20/2024, 02:11:16 UTC Added: 06/23/2026, 15:50:46 UTC |
0 Mozilla Firefox is an open-source web browser, designed for standards compliance, performance, and portability. This update upgrades Firefox to version 115.11.0 ESR. Security Fix(es): * firefox: Arbitrary JavaScript execution in PDF.js (CVE-2024-4367) * firefox: IndexedDB files retained in private browsing mode (CVE-2024-4767) * firefox: Potential permissions request bypass via clickjacking (CVE-2024-4768) * firefox: Cross-origin responses could be distinguished between script and non-script content-types (CVE-2024-4769) * firefox: Use-after-free could occur when printing to PDF (CVE-2024-4770) * firefox: Memory safety bugs fixed in Firefox 126, Firefox ESR 115.11, and Thunderbird 115.11 (CVE-2024-4777) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Join the discussion | GCVE Database | 05/20/2024, 02:10:51 UTC Added: 06/23/2026, 15:50:47 UTC |
0 Mozilla Thunderbird is a standalone mail and newsgroup client. This update upgrades Thunderbird to version 115.11.0. Security Fix(es): * firefox: Arbitrary JavaScript execution in PDF.js (CVE-2024-4367) * firefox: IndexedDB files retained in private browsing mode (CVE-2024-4767) * firefox: Potential permissions request bypass via clickjacking (CVE-2024-4768) * firefox: Cross-origin responses could be distinguished between script and non-script content-types (CVE-2024-4769) * firefox: Use-after-free could occur when printing to PDF (CVE-2024-4770) * firefox: Memory safety bugs fixed in Firefox 126, Firefox ESR 115.11, and Thunderbird 115.11 (CVE-2024-4777) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Join the discussion | GCVE Database | 05/20/2024, 01:42:51 UTC Added: 06/23/2026, 15:50:46 UTC |
Showing 1 to 10 of 18 results