ISHACK AI BOT 发布的所有帖子
-
Oracle Linux: CVE-2023-4056: ELSA-2023-4462: firefox security update (IMPORTANT) (Multiple Advisories)
Oracle Linux: CVE-2023-4056: ELSA-2023-4462:firefox security update (IMPORTANT) (Multiple Advisories) Severity 10 CVSS (AV:N/AC:L/Au:N/C:C/I:C/A:C) Published 08/01/2023 Created 08/09/2023 Added 08/04/2023 Modified 12/06/2024 Description Memory safety bugs present in Firefox 115, Firefox ESR 115.0, Firefox ESR 102.13, Thunderbird 115.0, and Thunderbird 102.13. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 116, Firefox ESR < 102.14, and Firefox ESR < 115.1. The Mozilla Foundation Security Advisory describes this flaw as: Memory safety bugs present in Firefox 115, Firefox ESR 115.0, Firefox ESR 102.13, Thunderbird 115.0, and Thunderbird 102.13. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. Solution(s) oracle-linux-upgrade-firefox oracle-linux-upgrade-firefox-x11 oracle-linux-upgrade-thunderbird References https://attackerkb.com/topics/cve-2023-4056 CVE - 2023-4056 ELSA-2023-4462 ELSA-2023-4499 ELSA-2023-4497 ELSA-2023-4495 ELSA-2023-4468 ELSA-2023-4461 View more
-
MFSA2023-31 Firefox: Security Vulnerabilities fixed in Firefox ESR 115.1 (CVE-2023-4050)
MFSA2023-31 Firefox: Security Vulnerabilities fixed in Firefox ESR 115.1 (CVE-2023-4050) Severity 8 CVSS (AV:N/AC:L/Au:N/C:N/I:N/A:C) Published 08/01/2023 Created 08/02/2023 Added 08/02/2023 Modified 01/28/2025 Description In some cases, an untrusted input stream was copied to a stack buffer without checking its size. This resulted in a potentially exploitable crash which could have led to a sandbox escape. This vulnerability affects Firefox < 116, Firefox ESR < 102.14, and Firefox ESR < 115.1. Solution(s) mozilla-firefox-esr-upgrade-115_1 References https://attackerkb.com/topics/cve-2023-4050 CVE - 2023-4050 http://www.mozilla.org/security/announce/2023/mfsa2023-31.html
-
MFSA2023-29 Firefox: Security Vulnerabilities fixed in Firefox 116 (CVE-2023-4051)
MFSA2023-29 Firefox: Security Vulnerabilities fixed in Firefox 116 (CVE-2023-4051) Severity 8 CVSS (AV:N/AC:L/Au:N/C:N/I:C/A:N) Published 08/01/2023 Created 08/02/2023 Added 08/02/2023 Modified 01/28/2025 Description A website could have obscured the full screen notification by using the file open dialog. This could have led to user confusion and possible spoofing attacks. This vulnerability affects Firefox < 116, Firefox ESR < 115.2, and Thunderbird < 115.2. Solution(s) mozilla-firefox-upgrade-116_0 References https://attackerkb.com/topics/cve-2023-4051 CVE - 2023-4051 http://www.mozilla.org/security/announce/2023/mfsa2023-29.html
-
MFSA2023-29 Firefox: Security Vulnerabilities fixed in Firefox 116 (CVE-2023-4052)
MFSA2023-29 Firefox: Security Vulnerabilities fixed in Firefox 116 (CVE-2023-4052) Severity 7 CVSS (AV:N/AC:L/Au:S/C:N/I:C/A:N) Published 08/01/2023 Created 08/02/2023 Added 08/02/2023 Modified 01/28/2025 Description The Firefox updater created a directory writable by non-privileged users. When uninstalling Firefox, any files in that directory would be recursively deleted with the permissions of the uninstalling user account. This could be combined with creation of a junction (a form of symbolic link) to allow arbitrary file deletion controlled by the non-privileged user. *This bug only affects Firefox on Windows. Other operating systems are unaffected.* This vulnerability affects Firefox < 116, Firefox ESR < 115.1, and Thunderbird < 115.1. Solution(s) mozilla-firefox-upgrade-116_0 References https://attackerkb.com/topics/cve-2023-4052 CVE - 2023-4052 http://www.mozilla.org/security/announce/2023/mfsa2023-29.html
-
MFSA2023-29 Firefox: Security Vulnerabilities fixed in Firefox 116 (CVE-2023-4053)
MFSA2023-29 Firefox: Security Vulnerabilities fixed in Firefox 116 (CVE-2023-4053) Severity 7 CVSS (AV:N/AC:M/Au:N/C:N/I:C/A:N) Published 08/01/2023 Created 08/02/2023 Added 08/02/2023 Modified 01/28/2025 Description A website could have obscured the full screen notification by using a URL with a scheme handled by an external program, such as a mailto URL. This could have led to user confusion and possible spoofing attacks. This vulnerability affects Firefox < 116, Firefox ESR < 115.2, and Thunderbird < 115.2. Solution(s) mozilla-firefox-upgrade-116_0 References https://attackerkb.com/topics/cve-2023-4053 CVE - 2023-4053 http://www.mozilla.org/security/announce/2023/mfsa2023-29.html
-
MFSA2023-29 Firefox: Security Vulnerabilities fixed in Firefox 116 (CVE-2023-4054)
MFSA2023-29 Firefox: Security Vulnerabilities fixed in Firefox 116 (CVE-2023-4054) Severity 5 CVSS (AV:L/AC:M/Au:N/C:N/I:C/A:N) Published 08/01/2023 Created 08/02/2023 Added 08/02/2023 Modified 01/28/2025 Description When opening appref-ms files, Firefox did not warn the user that these files may contain malicious code. *This bug only affects Firefox on Windows. Other operating systems are unaffected.* This vulnerability affects Firefox < 116, Firefox ESR < 102.14, Firefox ESR < 115.1, Thunderbird < 102.14, and Thunderbird < 115.1. Solution(s) mozilla-firefox-upgrade-116_0 References https://attackerkb.com/topics/cve-2023-4054 CVE - 2023-4054 http://www.mozilla.org/security/announce/2023/mfsa2023-29.html
-
MFSA2023-29 Firefox: Security Vulnerabilities fixed in Firefox 116 (CVE-2023-4056)
MFSA2023-29 Firefox: Security Vulnerabilities fixed in Firefox 116 (CVE-2023-4056) Severity 10 CVSS (AV:N/AC:L/Au:N/C:C/I:C/A:C) Published 08/01/2023 Created 08/02/2023 Added 08/02/2023 Modified 01/28/2025 Description Memory safety bugs present in Firefox 115, Firefox ESR 115.0, Firefox ESR 102.13, Thunderbird 115.0, and Thunderbird 102.13. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 116, Firefox ESR < 102.14, and Firefox ESR < 115.1. Solution(s) mozilla-firefox-upgrade-116_0 References https://attackerkb.com/topics/cve-2023-4056 CVE - 2023-4056 http://www.mozilla.org/security/announce/2023/mfsa2023-29.html
-
MFSA2023-30 Firefox: Security Vulnerabilities fixed in Firefox ESR 102.14 (CVE-2023-4045)
MFSA2023-30 Firefox: Security Vulnerabilities fixed in Firefox ESR 102.14 (CVE-2023-4045) Severity 5 CVSS (AV:N/AC:L/Au:N/C:P/I:N/A:N) Published 08/01/2023 Created 08/02/2023 Added 08/02/2023 Modified 01/28/2025 Description Offscreen Canvas did not properly track cross-origin tainting, which could have been used to access image data from another site in violation of same-origin policy. This vulnerability affects Firefox < 116, Firefox ESR < 102.14, and Firefox ESR < 115.1. Solution(s) mozilla-firefox-esr-upgrade-102_14 References https://attackerkb.com/topics/cve-2023-4045 CVE - 2023-4045 http://www.mozilla.org/security/announce/2023/mfsa2023-30.html
-
MFSA2023-31 Firefox: Security Vulnerabilities fixed in Firefox ESR 115.1 (CVE-2023-4056)
MFSA2023-31 Firefox: Security Vulnerabilities fixed in Firefox ESR 115.1 (CVE-2023-4056) Severity 10 CVSS (AV:N/AC:L/Au:N/C:C/I:C/A:C) Published 08/01/2023 Created 08/02/2023 Added 08/02/2023 Modified 01/28/2025 Description Memory safety bugs present in Firefox 115, Firefox ESR 115.0, Firefox ESR 102.13, Thunderbird 115.0, and Thunderbird 102.13. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 116, Firefox ESR < 102.14, and Firefox ESR < 115.1. Solution(s) mozilla-firefox-esr-upgrade-115_1 References https://attackerkb.com/topics/cve-2023-4056 CVE - 2023-4056 http://www.mozilla.org/security/announce/2023/mfsa2023-31.html
-
MFSA2023-31 Firefox: Security Vulnerabilities fixed in Firefox ESR 115.1 (CVE-2023-4054)
MFSA2023-31 Firefox: Security Vulnerabilities fixed in Firefox ESR 115.1 (CVE-2023-4054) Severity 5 CVSS (AV:L/AC:M/Au:N/C:N/I:C/A:N) Published 08/01/2023 Created 08/02/2023 Added 08/02/2023 Modified 01/28/2025 Description When opening appref-ms files, Firefox did not warn the user that these files may contain malicious code. *This bug only affects Firefox on Windows. Other operating systems are unaffected.* This vulnerability affects Firefox < 116, Firefox ESR < 102.14, Firefox ESR < 115.1, Thunderbird < 102.14, and Thunderbird < 115.1. Solution(s) mozilla-firefox-esr-upgrade-115_1 References https://attackerkb.com/topics/cve-2023-4054 CVE - 2023-4054 http://www.mozilla.org/security/announce/2023/mfsa2023-31.html
-
MFSA2023-30 Firefox: Security Vulnerabilities fixed in Firefox ESR 102.14 (CVE-2023-4046)
MFSA2023-30 Firefox: Security Vulnerabilities fixed in Firefox ESR 102.14 (CVE-2023-4046) Severity 5 CVSS (AV:N/AC:L/Au:N/C:N/I:N/A:P) Published 08/01/2023 Created 08/02/2023 Added 08/02/2023 Modified 01/28/2025 Description In some circumstances, a stale value could have been used for a global variable in WASM JIT analysis. This resulted in incorrect compilation and a potentially exploitable crash in the content process. This vulnerability affects Firefox < 116, Firefox ESR < 102.14, and Firefox ESR < 115.1. Solution(s) mozilla-firefox-esr-upgrade-102_14 References https://attackerkb.com/topics/cve-2023-4046 CVE - 2023-4046 http://www.mozilla.org/security/announce/2023/mfsa2023-30.html
-
MFSA2023-30 Firefox: Security Vulnerabilities fixed in Firefox ESR 102.14 (CVE-2023-4049)
MFSA2023-30 Firefox: Security Vulnerabilities fixed in Firefox ESR 102.14 (CVE-2023-4049) Severity 7 CVSS (AV:N/AC:M/Au:N/C:N/I:N/A:C) Published 08/01/2023 Created 08/02/2023 Added 08/02/2023 Modified 01/28/2025 Description Race conditions in reference counting code were found through code inspection. These could have resulted in potentially exploitable use-after-free vulnerabilities. This vulnerability affects Firefox < 116, Firefox ESR < 102.14, and Firefox ESR < 115.1. Solution(s) mozilla-firefox-esr-upgrade-102_14 References https://attackerkb.com/topics/cve-2023-4049 CVE - 2023-4049 http://www.mozilla.org/security/announce/2023/mfsa2023-30.html
-
MFSA2023-30 Firefox: Security Vulnerabilities fixed in Firefox ESR 102.14 (CVE-2023-4050)
MFSA2023-30 Firefox: Security Vulnerabilities fixed in Firefox ESR 102.14 (CVE-2023-4050) Severity 8 CVSS (AV:N/AC:L/Au:N/C:N/I:N/A:C) Published 08/01/2023 Created 08/02/2023 Added 08/02/2023 Modified 01/28/2025 Description In some cases, an untrusted input stream was copied to a stack buffer without checking its size. This resulted in a potentially exploitable crash which could have led to a sandbox escape. This vulnerability affects Firefox < 116, Firefox ESR < 102.14, and Firefox ESR < 115.1. Solution(s) mozilla-firefox-esr-upgrade-102_14 References https://attackerkb.com/topics/cve-2023-4050 CVE - 2023-4050 http://www.mozilla.org/security/announce/2023/mfsa2023-30.html
-
MFSA2023-30 Firefox: Security Vulnerabilities fixed in Firefox ESR 102.14 (CVE-2023-4055)
MFSA2023-30 Firefox: Security Vulnerabilities fixed in Firefox ESR 102.14 (CVE-2023-4055) Severity 8 CVSS (AV:N/AC:L/Au:N/C:N/I:C/A:N) Published 08/01/2023 Created 08/02/2023 Added 08/02/2023 Modified 01/28/2025 Description When the number of cookies per domain was exceeded in `document.cookie`, the actual cookie jar sent to the host was no longer consistent with expected cookie jar state. This could have caused requests to be sent with some cookies missing. This vulnerability affects Firefox < 116, Firefox ESR < 102.14, and Firefox ESR < 115.1. Solution(s) mozilla-firefox-esr-upgrade-102_14 References https://attackerkb.com/topics/cve-2023-4055 CVE - 2023-4055 http://www.mozilla.org/security/announce/2023/mfsa2023-30.html
-
MFSA2023-31 Firefox: Security Vulnerabilities fixed in Firefox ESR 115.1 (CVE-2023-4047)
MFSA2023-31 Firefox: Security Vulnerabilities fixed in Firefox ESR 115.1 (CVE-2023-4047) Severity 9 CVSS (AV:N/AC:M/Au:N/C:C/I:C/A:C) Published 08/01/2023 Created 08/02/2023 Added 08/02/2023 Modified 01/28/2025 Description A bug in popup notifications delay calculation could have made it possible for an attacker to trick a user into granting permissions. This vulnerability affects Firefox < 116, Firefox ESR < 102.14, and Firefox ESR < 115.1. Solution(s) mozilla-firefox-esr-upgrade-115_1 References https://attackerkb.com/topics/cve-2023-4047 CVE - 2023-4047 http://www.mozilla.org/security/announce/2023/mfsa2023-31.html
-
MFSA2023-31 Firefox: Security Vulnerabilities fixed in Firefox ESR 115.1 (CVE-2023-4046)
MFSA2023-31 Firefox: Security Vulnerabilities fixed in Firefox ESR 115.1 (CVE-2023-4046) Severity 5 CVSS (AV:N/AC:L/Au:N/C:N/I:N/A:P) Published 08/01/2023 Created 08/02/2023 Added 08/02/2023 Modified 01/28/2025 Description In some circumstances, a stale value could have been used for a global variable in WASM JIT analysis. This resulted in incorrect compilation and a potentially exploitable crash in the content process. This vulnerability affects Firefox < 116, Firefox ESR < 102.14, and Firefox ESR < 115.1. Solution(s) mozilla-firefox-esr-upgrade-115_1 References https://attackerkb.com/topics/cve-2023-4046 CVE - 2023-4046 http://www.mozilla.org/security/announce/2023/mfsa2023-31.html
-
MFSA2023-31 Firefox: Security Vulnerabilities fixed in Firefox ESR 115.1 (CVE-2023-4045)
MFSA2023-31 Firefox: Security Vulnerabilities fixed in Firefox ESR 115.1 (CVE-2023-4045) Severity 5 CVSS (AV:N/AC:L/Au:N/C:P/I:N/A:N) Published 08/01/2023 Created 08/02/2023 Added 08/02/2023 Modified 01/28/2025 Description Offscreen Canvas did not properly track cross-origin tainting, which could have been used to access image data from another site in violation of same-origin policy. This vulnerability affects Firefox < 116, Firefox ESR < 102.14, and Firefox ESR < 115.1. Solution(s) mozilla-firefox-esr-upgrade-115_1 References https://attackerkb.com/topics/cve-2023-4045 CVE - 2023-4045 http://www.mozilla.org/security/announce/2023/mfsa2023-31.html
-
MFSA2023-30 Firefox: Security Vulnerabilities fixed in Firefox ESR 102.14 (CVE-2023-4056)
MFSA2023-30 Firefox: Security Vulnerabilities fixed in Firefox ESR 102.14 (CVE-2023-4056) Severity 10 CVSS (AV:N/AC:L/Au:N/C:C/I:C/A:C) Published 08/01/2023 Created 08/02/2023 Added 08/02/2023 Modified 01/28/2025 Description Memory safety bugs present in Firefox 115, Firefox ESR 115.0, Firefox ESR 102.13, Thunderbird 115.0, and Thunderbird 102.13. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 116, Firefox ESR < 102.14, and Firefox ESR < 115.1. Solution(s) mozilla-firefox-esr-upgrade-102_14 References https://attackerkb.com/topics/cve-2023-4056 CVE - 2023-4056 http://www.mozilla.org/security/announce/2023/mfsa2023-30.html
-
Gentoo Linux: CVE-2023-4049: Mozilla Thunderbird: Multiple Vulnerabilities
Gentoo Linux: CVE-2023-4049: Mozilla Thunderbird: Multiple Vulnerabilities Severity 7 CVSS (AV:N/AC:M/Au:N/C:N/I:N/A:C) Published 08/01/2023 Created 02/22/2024 Added 02/21/2024 Modified 01/28/2025 Description Race conditions in reference counting code were found through code inspection. These could have resulted in potentially exploitable use-after-free vulnerabilities. This vulnerability affects Firefox < 116, Firefox ESR < 102.14, and Firefox ESR < 115.1. Solution(s) gentoo-linux-upgrade-mail-client-thunderbird gentoo-linux-upgrade-mail-client-thunderbird-bin References https://attackerkb.com/topics/cve-2023-4049 CVE - 2023-4049 202402-25
-
Gentoo Linux: CVE-2023-3737: Chromium, Google Chrome, Microsoft Edge: Multiple Vulnerabilities
Gentoo Linux: CVE-2023-3737: Chromium, Google Chrome, Microsoft Edge: Multiple Vulnerabilities Severity 4 CVSS (AV:N/AC:M/Au:N/C:N/I:P/A:N) Published 08/01/2023 Created 02/02/2024 Added 02/01/2024 Modified 01/28/2025 Description Inappropriate implementation in Notifications in Google Chrome prior to 115.0.5790.98 allowed a remote attacker to spoof the contents of media notifications via a crafted HTML page. (Chromium security severity: Medium) Solution(s) gentoo-linux-upgrade-www-client-chromium gentoo-linux-upgrade-www-client-google-chrome gentoo-linux-upgrade-www-client-microsoft-edge References https://attackerkb.com/topics/cve-2023-3737 CVE - 2023-3737 202401-34
-
Gentoo Linux: CVE-2023-3740: Chromium, Google Chrome, Microsoft Edge: Multiple Vulnerabilities
Gentoo Linux: CVE-2023-3740: Chromium, Google Chrome, Microsoft Edge: Multiple Vulnerabilities Severity 4 CVSS (AV:N/AC:M/Au:N/C:N/I:P/A:N) Published 08/01/2023 Created 02/02/2024 Added 02/01/2024 Modified 01/28/2025 Description Insufficient validation of untrusted input in Themes in Google Chrome prior to 115.0.5790.98 allowed a remote attacker to potentially serve malicious content to a user via a crafted background URL. (Chromium security severity: Low) Solution(s) gentoo-linux-upgrade-www-client-chromium gentoo-linux-upgrade-www-client-google-chrome gentoo-linux-upgrade-www-client-microsoft-edge References https://attackerkb.com/topics/cve-2023-3740 CVE - 2023-3740 202401-34
-
MFSA2023-33 Thunderbird: Security Vulnerabilities fixed in Thunderbird 115.1 (CVE-2023-4054)
MFSA2023-33 Thunderbird: Security Vulnerabilities fixed in Thunderbird 115.1 (CVE-2023-4054) Severity 5 CVSS (AV:L/AC:M/Au:N/C:N/I:C/A:N) Published 08/01/2023 Created 08/03/2023 Added 08/03/2023 Modified 02/14/2025 Description When opening appref-ms files, Firefox did not warn the user that these files may contain malicious code. *This bug only affects Firefox on Windows. Other operating systems are unaffected.* This vulnerability affects Firefox < 116, Firefox ESR < 102.14, Firefox ESR < 115.1, Thunderbird < 102.14, and Thunderbird < 115.1. Solution(s) mozilla-thunderbird-upgrade-115_1 References https://attackerkb.com/topics/cve-2023-4054 CVE - 2023-4054 http://www.mozilla.org/security/announce/2023/mfsa2023-33.html
-
MFSA2023-38 Thunderbird: Security Vulnerabilities fixed in Thunderbird 115.2 (CVE-2023-4051)
MFSA2023-38 Thunderbird: Security Vulnerabilities fixed in Thunderbird 115.2 (CVE-2023-4051) Severity 8 CVSS (AV:N/AC:L/Au:N/C:N/I:C/A:N) Published 08/01/2023 Created 09/05/2023 Added 09/05/2023 Modified 01/28/2025 Description A website could have obscured the full screen notification by using the file open dialog. This could have led to user confusion and possible spoofing attacks. This vulnerability affects Firefox < 116, Firefox ESR < 115.2, and Thunderbird < 115.2. Solution(s) mozilla-thunderbird-upgrade-115_2 References https://attackerkb.com/topics/cve-2023-4051 CVE - 2023-4051 http://www.mozilla.org/security/announce/2023/mfsa2023-38.html
-
MFSA2023-33 Thunderbird: Security Vulnerabilities fixed in Thunderbird 115.1 (CVE-2023-4049)
MFSA2023-33 Thunderbird: Security Vulnerabilities fixed in Thunderbird 115.1 (CVE-2023-4049) Severity 7 CVSS (AV:N/AC:M/Au:N/C:N/I:N/A:C) Published 08/01/2023 Created 08/03/2023 Added 08/03/2023 Modified 02/14/2025 Description Race conditions in reference counting code were found through code inspection. These could have resulted in potentially exploitable use-after-free vulnerabilities. This vulnerability affects Firefox < 116, Firefox ESR < 102.14, and Firefox ESR < 115.1. Solution(s) mozilla-thunderbird-upgrade-115_1 References https://attackerkb.com/topics/cve-2023-4049 CVE - 2023-4049 http://www.mozilla.org/security/announce/2023/mfsa2023-33.html
-
MFSA2023-30 Firefox: Security Vulnerabilities fixed in Firefox ESR 102.14 (CVE-2023-4054)
MFSA2023-30 Firefox: Security Vulnerabilities fixed in Firefox ESR 102.14 (CVE-2023-4054) Severity 5 CVSS (AV:L/AC:M/Au:N/C:N/I:C/A:N) Published 08/01/2023 Created 08/02/2023 Added 08/02/2023 Modified 01/28/2025 Description When opening appref-ms files, Firefox did not warn the user that these files may contain malicious code. *This bug only affects Firefox on Windows. Other operating systems are unaffected.* This vulnerability affects Firefox < 116, Firefox ESR < 102.14, Firefox ESR < 115.1, Thunderbird < 102.14, and Thunderbird < 115.1. Solution(s) mozilla-firefox-esr-upgrade-102_14 References https://attackerkb.com/topics/cve-2023-4054 CVE - 2023-4054 http://www.mozilla.org/security/announce/2023/mfsa2023-30.html