CVE-2024-1563
published 2024-02-22CVE-2024-1563: An attacker could have executed unauthorized scripts on top origin sites using a JavaScript URI when opening an external URL with a custom Firefox scheme and a…
PriorityP343high8.1CVSS 3.1
AVNACHPRNUINSUCHIHAH
EPSS
0.39%
30.9th percentile
An attacker could have executed unauthorized scripts on top origin sites using a JavaScript URI when opening an external URL with a custom Firefox scheme and a timeout race condition. This vulnerability affects Focus for iOS < 122.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mozilla | firefox | — | — |
| mozilla | firefox_focus | < 122.0 | 122.0 |
| mozilla | focus_for_ios | >= unspecified < 122 | 122 |
CVSS provenance
nvdv3.18.1HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-783m-f4c2-pgqr: An attacker could have executed unauthorized scripts on top origin sites using a JavaScript URI when opening an external URL with a custom Firefox sch
ghsa_unreviewed·2024-02-22
CVE-2024-1563 [HIGH] CWE-367 GHSA-783m-f4c2-pgqr: An attacker could have executed unauthorized scripts on top origin sites using a JavaScript URI when opening an external URL with a custom Firefox sch
An attacker could have executed unauthorized scripts on top origin sites using a JavaScript URI when opening an external URL with a custom Firefox scheme and a timeout race condition. This vulnerability affects Focus for iOS < 122.
Red Hat
kernel: net/smc: do not leave a dangling sk pointer in __smc_create()
vendor_redhat·2024-11-19·CVSS 7.8
CVE-2024-50293 [HIGH] kernel: net/smc: do not leave a dangling sk pointer in __smc_create()
kernel: net/smc: do not leave a dangling sk pointer in __smc_create()
In the Linux kernel, the following vulnerability has been resolved:
net/smc: do not leave a dangling sk pointer in __smc_create()
Thanks to commit 4bbd360a5084 ("socket: Print pf->create() when
it does not clear sock->sk on failure."), syzbot found an issue with AF_SMC:
smc_create must clear sock->sk on failure, family: 43, type: 1, protocol: 0
WARNING: CPU: 0 PID: 5827 at net/socket.c:1565 __sock_create+0x96f/0xa30 net/socket.c:1563
Modules linked in:
CPU: 0 UID: 0 PID: 5827 Comm: syz-executor259 Not tainted 6.12.0-rc6-next-20241106-syzkaller #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 09/13/2024
RIP: 0010:__sock_create+0x96f/0xa30 net/socket.c:1563
Code: 03 00 74 08 4c 89 e7 e8 4f
Mozilla
Mozilla Foundation Security Advisory 2024-09: CVE-2024-1563
vendor_mozilla·CVSS 8.1
CVE-2024-1563 [HIGH] Mozilla Foundation Security Advisory 2024-09: CVE-2024-1563
Mozilla Foundation Security Advisory 2024-09
CVE: CVE-2024-1563
Product: Focus for iOS
Impact: high
Fixed in: Focus for iOS 122
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2024-02-22
Published