Skip to main content

Threats Tagged 'cve-2024-4777'

View all threats tagged with 'cve-2024-4777'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: cve-2024-4777

Threats Tagged 'cve-2024-4777'

Click on any threat for detailed analysis and mitigation recommendations

0

This update for webkit2gtk3 fixes the following issues: - CVE-2024-4367: missing type check when handling fonts in PDF.js can allow arbitrary JavaScript execution (bsc#1271638). - CVE-2026-39872: maliciously crafted web content can lead to an unexpected process crash (bsc#1271638). - CVE-2026-43663: maliciously crafted web content can lead to an unexpected process crash (bsc#1271638). - CVE-2026-43676: out-of-bounds access when processing web content can lead to an unexpected Safari crash (bsc#1271638). - CVE-2026-43699: use-after-free issue when processing web content can lead to an unexpected process crash (bsc#1271638). - CVE-2026-43701: malicious website can process restricted web content outside the sandbox (bsc#1271638). - CVE-2026-43705: type confusion issue when processing web content can lead to memory corruption (bsc#1271638). - CVE-2026-43707: memory corruption issue when processing web content can lead to an unexpected process crash (bsc#1271638). - CVE-2026-43712: maliciously crafted web content can lead to an unexpected process crash (bsc#1271638). - CVE-2026-43713: visiting a website can leak sensitive data due to a permissions issue (bsc#1271638). - CVE-2026-43715: use-after-free issue when processing web content can lead to memory corruption (bsc#1271638). - CVE-2026-43716: maliciously crafted web content can lead to an unexpected Safari crash (bsc#1271638). - CVE-2026-43720: use-after-free issue when processing web content can lead to an unexpected Safari crash (bsc#1271638). - CVE-2026-43721: malicious website can silently hijack clipboard data (bsc#1271638). - CVE-2026-43725: unvalidated input can allow a malicious website to process restricted web content outside the sandbox (bsc#1271638). - CVE-2026-43726: use-after-free issue when processing web content can lead to an unexpected process crash (bsc#1271638). - CVE-2026-43727: use-after-free issue when processing web content can lead to an unexpected Safari crash (bsc#1271638). - CVE-2026-43731: use-after-free issue when processing web content can lead to memory corruption (bsc#1271638). - CVE-2026-43732: path handling issue when processing web content can disclose sensitive user information (bsc#1271638). - CVE-2026-43734: use-after-free issue when processing web content can lead to an unexpected process crash (bsc#1271638). - CVE-2026-43740: maliciously crafted web content can result in the disclosure of process memory (bsc#1271638). - CVE-2026-43742: use-after-free issue when processing web content can lead to an unexpected process crash (bsc#1271638). - CVE-2026-43745: out-of-bounds write issue when processing web content can lead to an unexpected Safari crash (bsc#1271638). Changes for webkit2gtk3: - Update to version 2.52.5: * Fire scrollend event for instant programmatic scrolls. * Increase network idle connection timeout to 115 seconds. * Add User-Agent quirk for HBO Max. * Fix the build with system malloc.

Join the discussion
0

This update for webkit2gtk3 fixes the following issues: - CVE-2024-4367: missing type check when handling fonts in PDF.js can allow arbitrary JavaScript execution (bsc#1271638). - CVE-2026-39872: maliciously crafted web content can lead to an unexpected process crash (bsc#1271638). - CVE-2026-43663: maliciously crafted web content can lead to an unexpected process crash (bsc#1271638). - CVE-2026-43676: out-of-bounds access when processing web content can lead to an unexpected Safari crash (bsc#1271638). - CVE-2026-43699: use-after-free issue when processing web content can lead to an unexpected process crash (bsc#1271638). - CVE-2026-43701: malicious website can process restricted web content outside the sandbox (bsc#1271638). - CVE-2026-43705: type confusion issue when processing web content can lead to memory corruption (bsc#1271638). - CVE-2026-43707: memory corruption issue when processing web content can lead to an unexpected process crash (bsc#1271638). - CVE-2026-43712: maliciously crafted web content can lead to an unexpected process crash (bsc#1271638). - CVE-2026-43713: visiting a website can leak sensitive data due to a permissions issue (bsc#1271638). - CVE-2026-43715: use-after-free issue when processing web content can lead to memory corruption (bsc#1271638). - CVE-2026-43716: maliciously crafted web content can lead to an unexpected Safari crash (bsc#1271638). - CVE-2026-43720: use-after-free issue when processing web content can lead to an unexpected Safari crash (bsc#1271638). - CVE-2026-43721: malicious website can silently hijack clipboard data (bsc#1271638). - CVE-2026-43725: unvalidated input can allow a malicious website to process restricted web content outside the sandbox (bsc#1271638). - CVE-2026-43726: use-after-free issue when processing web content can lead to an unexpected process crash (bsc#1271638). - CVE-2026-43727: use-after-free issue when processing web content can lead to an unexpected Safari crash (bsc#1271638). - CVE-2026-43731: use-after-free issue when processing web content can lead to memory corruption (bsc#1271638). - CVE-2026-43732: path handling issue when processing web content can disclose sensitive user information (bsc#1271638). - CVE-2026-43734: use-after-free issue when processing web content can lead to an unexpected process crash (bsc#1271638). - CVE-2026-43740: maliciously crafted web content can result in the disclosure of process memory (bsc#1271638). - CVE-2026-43742: use-after-free issue when processing web content can lead to an unexpected process crash (bsc#1271638). - CVE-2026-43745: out-of-bounds write issue when processing web content can lead to an unexpected Safari crash (bsc#1271638). Changes for webkit2gtk3: - Update to version 2.52.5: * Fire scrollend event for instant programmatic scrolls. * Increase network idle connection timeout to 115 seconds. * Add User-Agent quirk for HBO Max. * Fix the build with system malloc.

Join the discussion
0

Mozilla Firefox is an open-source web browser, designed for standards compliance, performance, and portability. This update upgrades Firefox to version 115.11.0 ESR. Security Fix(es): * firefox: Arbitrary JavaScript execution in PDF.js (CVE-2024-4367) * firefox: IndexedDB files retained in private browsing mode (CVE-2024-4767) * firefox: Potential permissions request bypass via clickjacking (CVE-2024-4768) * firefox: Cross-origin responses could be distinguished between script and non-script content-types (CVE-2024-4769) * firefox: Use-after-free could occur when printing to PDF (CVE-2024-4770) * firefox: Memory safety bugs fixed in Firefox 126, Firefox ESR 115.11, and Thunderbird 115.11 (CVE-2024-4777) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Join the discussion
0

Mozilla Thunderbird is a standalone mail and newsgroup client. This update upgrades Thunderbird to version 115.11.0. Security Fix(es): * Mozilla: Arbitrary JavaScript execution in PDF.js (CVE-2024-4367) * Mozilla: IndexedDB files retained in private browsing mode (CVE-2024-4767) * Mozilla: Potential permissions request bypass via clickjacking (CVE-2024-4768) * Mozilla: Cross-origin responses could be distinguished between script and non-script content-types (CVE-2024-4769) * Mozilla: Use-after-free could occur when printing to PDF (CVE-2024-4770) * Mozilla: Memory safety bugs fixed in Firefox 126, Firefox ESR 115.11, and Thunderbird 115.11 (CVE-2024-4777) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Join the discussion
0

Mozilla Thunderbird is a standalone mail and newsgroup client. This update upgrades Thunderbird to version 115.11.0. Security Fix(es): * firefox: Arbitrary JavaScript execution in PDF.js (CVE-2024-4367) * firefox: IndexedDB files retained in private browsing mode (CVE-2024-4767) * firefox: Potential permissions request bypass via clickjacking (CVE-2024-4768) * firefox: Cross-origin responses could be distinguished between script and non-script content-types (CVE-2024-4769) * firefox: Use-after-free could occur when printing to PDF (CVE-2024-4770) * firefox: Memory safety bugs fixed in Firefox 126, Firefox ESR 115.11, and Thunderbird 115.11 (CVE-2024-4777) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Join the discussion
0

Mozilla Thunderbird is a standalone mail and newsgroup client. This update upgrades Thunderbird to version 115.11.0. Security Fix(es): * firefox: Arbitrary JavaScript execution in PDF.js (CVE-2024-4367) * firefox: IndexedDB files retained in private browsing mode (CVE-2024-4767) * firefox: Potential permissions request bypass via clickjacking (CVE-2024-4768) * firefox: Cross-origin responses could be distinguished between script and non-script content-types (CVE-2024-4769) * firefox: Use-after-free could occur when printing to PDF (CVE-2024-4770) * firefox: Memory safety bugs fixed in Firefox 126, Firefox ESR 115.11, and Thunderbird 115.11 (CVE-2024-4777) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Join the discussion
0

Mozilla Thunderbird is a standalone mail and newsgroup client. This update upgrades Thunderbird to version 115.11.0. Security Fix(es): * firefox: Arbitrary JavaScript execution in PDF.js (CVE-2024-4367) * firefox: IndexedDB files retained in private browsing mode (CVE-2024-4767) * firefox: Potential permissions request bypass via clickjacking (CVE-2024-4768) * firefox: Cross-origin responses could be distinguished between script and non-script content-types (CVE-2024-4769) * firefox: Use-after-free could occur when printing to PDF (CVE-2024-4770) * firefox: Memory safety bugs fixed in Firefox 126, Firefox ESR 115.11, and Thunderbird 115.11 (CVE-2024-4777) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Join the discussion
0

Mozilla Thunderbird is a standalone mail and newsgroup client. This update upgrades Thunderbird to version 115.11.0. Security Fix(es): * firefox: Arbitrary JavaScript execution in PDF.js (CVE-2024-4367) * firefox: IndexedDB files retained in private browsing mode (CVE-2024-4767) * firefox: Potential permissions request bypass via clickjacking (CVE-2024-4768) * firefox: Cross-origin responses could be distinguished between script and non-script content-types (CVE-2024-4769) * firefox: Use-after-free could occur when printing to PDF (CVE-2024-4770) * firefox: Memory safety bugs fixed in Firefox 126, Firefox ESR 115.11, and Thunderbird 115.11 (CVE-2024-4777) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Join the discussion
0

Mozilla Firefox is an open-source web browser, designed for standards compliance, performance, and portability. This update upgrades Firefox to version 115.11.0 ESR. Security Fix(es): * firefox: Arbitrary JavaScript execution in PDF.js (CVE-2024-4367) * firefox: IndexedDB files retained in private browsing mode (CVE-2024-4767) * firefox: Potential permissions request bypass via clickjacking (CVE-2024-4768) * firefox: Cross-origin responses could be distinguished between script and non-script content-types (CVE-2024-4769) * firefox: Use-after-free could occur when printing to PDF (CVE-2024-4770) * firefox: Memory safety bugs fixed in Firefox 126, Firefox ESR 115.11, and Thunderbird 115.11 (CVE-2024-4777) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Join the discussion
0

Mozilla Thunderbird is a standalone mail and newsgroup client. This update upgrades Thunderbird to version 115.11.0. Security Fix(es): * firefox: Arbitrary JavaScript execution in PDF.js (CVE-2024-4367) * firefox: IndexedDB files retained in private browsing mode (CVE-2024-4767) * firefox: Potential permissions request bypass via clickjacking (CVE-2024-4768) * firefox: Cross-origin responses could be distinguished between script and non-script content-types (CVE-2024-4769) * firefox: Use-after-free could occur when printing to PDF (CVE-2024-4770) * firefox: Memory safety bugs fixed in Firefox 126, Firefox ESR 115.11, and Thunderbird 115.11 (CVE-2024-4777) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Join the discussion

Showing 1 to 10 of 18 results

Filters:Tag: cve-2024-4777
Page 1 of 2
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses