CVE-2024-5700
published 2024-06-11CVE-2024-5700: Memory safety bugs present in Firefox 126, Firefox ESR 115.11, and Thunderbird 115.11. Some of these bugs showed evidence of memory corruption and we presume…
high7CVSS 3.1
AVLACHPRNUIRSUCHIHAH
Memory safety bugs present in Firefox 126, Firefox ESR 115.11, and Thunderbird 115.11. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 127, Firefox ESR < 115.12, and Thunderbird < 115.12.
Affected
17 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | firefox | < firefox 127.0-1 (sid) | firefox 127.0-1 (sid) |
| debian | firefox-esr | < firefox 127.0-1 (sid) | firefox 127.0-1 (sid) |
| debian | thunderbird | < firefox 127.0-1 (sid) | firefox 127.0-1 (sid) |
| mozilla | firefox | < 115.12 | 115.12 |
| mozilla | firefox | < 127.0 | 127.0 |
| mozilla | firefox | — | — |
| mozilla | firefox | >= 0 < 127.0.2+build1-0ubuntu0.20.04.1 | 127.0.2+build1-0ubuntu0.20.04.1 |
| mozilla | firefox | >= unspecified < 127 | 127 |
| mozilla | firefox_esr | >= unspecified < 115.12 | 115.12 |
| mozilla | thunderbird | < 115.12 | 115.12 |
| mozilla | thunderbird | >= 0 < 1:115.12.0-1~deb11u1 | 1:115.12.0-1~deb11u1 |
| mozilla | thunderbird | >= 0 < 1:115.12.0-1~deb12u1 | 1:115.12.0-1~deb12u1 |
| mozilla | thunderbird | >= 0 < 1:115.12.0-1 | 1:115.12.0-1 |
| mozilla | thunderbird | >= 0 < 1:115.12.0-1 | 1:115.12.0-1 |
| mozilla | thunderbird | >= 0 < 1:115.12.0+build3-0ubuntu0.20.04.1 | 1:115.12.0+build3-0ubuntu0.20.04.1 |
| mozilla | thunderbird | >= 0 < 1:115.12.0+build3-0ubuntu0.22.04.1 | 1:115.12.0+build3-0ubuntu0.22.04.1 |
| mozilla | thunderbird | >= unspecified < 115.12 | 115.12 |
CVSS provenance
nvdv3.17.0HIGHCVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
osv8.1HIGH
OSV
firefox vulnerabilities
osv·2024-07-03·CVSS 8.1
CVE-2024-5689 [HIGH] firefox vulnerabilities
firefox vulnerabilities
Multiple security issues were discovered in Firefox. If a user were
tricked into opening a specially crafted website, an attacker could
potentially exploit these to cause a denial of service, obtain sensitive
information across domains, or execute arbitrary code. (CVE-2024-5689,
CVE-2024-5690, CVE-2024-5691, CVE-2024-5693, CVE-2024-5697, CVE-2024-5698,
CVE-2024-5699, CVE-2024-5700, CVE-2024-5701)
Lukas Bernhard discovered that Firefox did not properly manage memory
during garbage collection. An attacker could potentially exploit this
issue to cause a denial of service, or execute arbitrary code.
(CVE-2024-5688)
Lukas Bernhard discovered that Firefox did not properly manage memory in
the JavaScript engine. An attacker could potentially exploit this issue to
obtain
OSV
thunderbird vulnerabilities
osv·2024-06-19·CVSS 8.1
CVE-2024-5688 [HIGH] thunderbird vulnerabilities
thunderbird vulnerabilities
Multiple security issues were discovered in Thunderbird. If a user were
tricked into opening a specially crafted website in a browsing context, an
attacker could potentially exploit these to cause a denial of service,
obtain sensitive information, bypass security restrictions, cross-site
tracing, or execute arbitrary code.(CVE-2024-5688, CVE-2024-5690,
CVE-2024-5696, CVE-2024-5700, CVE-2024-5702)
Luan Herrera discovered that Thunderbird did not properly validate the
X-Frame-Options header inside sandboxed iframe. An attacker could
potentially exploit this issue to bypass sandbox restrictions to open a new
window. (CVE-2024-5691)
Kirtikumar Anandrao Ramchandani discovered that Thunderbird did not properly
track cross-origin tainting in Offscreen Canvas. An att
GHSA
GHSA-pq6v-hjqm-frww: Memory safety bugs present in Firefox 126, Firefox ESR 115
ghsa_unreviewed·2024-06-11
CVE-2024-5700 [HIGH] CWE-786 GHSA-pq6v-hjqm-frww: Memory safety bugs present in Firefox 126, Firefox ESR 115
Memory safety bugs present in Firefox 126, Firefox ESR 115.11, and Thunderbird 115.11. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 127 and Firefox ESR < 115.12.
OSV
CVE-2024-5700: Memory safety bugs present in Firefox 126, Firefox ESR 115
osv·2024-06-11·CVSS 7.0
CVE-2024-5700 [HIGH] CVE-2024-5700: Memory safety bugs present in Firefox 126, Firefox ESR 115
Memory safety bugs present in Firefox 126, Firefox ESR 115.11, and Thunderbird 115.11. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 127, Firefox ESR < 115.12, and Thunderbird < 115.12.
Ubuntu
Firefox vulnerabilities
vendor_ubuntu·2024-07-03·CVSS 8.1
CVE-2024-5693 [HIGH] Firefox vulnerabilities
Title: Firefox vulnerabilities
Summary: Several security issues were fixed in Firefox.
Multiple security issues were discovered in Firefox. If a user were
tricked into opening a specially crafted website, an attacker could
potentially exploit these to cause a denial of service, obtain sensitive
information across domains, or execute arbitrary code. (CVE-2024-5689,
CVE-2024-5690, CVE-2024-5691, CVE-2024-5693, CVE-2024-5697, CVE-2024-5698,
CVE-2024-5699, CVE-2024-5700, CVE-2024-5701)
Lukas Bernhard discovered that Firefox did not properly manage memory
during garbage collection. An attacker could potentially exploit this
issue to cause a denial of service, or execute arbitrary code.
(CVE-2024-5688)
Lukas Bernhard discovered that Firefox did not properly manage memory in
the JavaScript en
Ubuntu
Thunderbird vulnerabilities
vendor_ubuntu·2024-06-19·CVSS 8.1
CVE-2024-5688 [HIGH] Thunderbird vulnerabilities
Title: Thunderbird vulnerabilities
Summary: Several security issues were fixed in Thunderbird.
Multiple security issues were discovered in Thunderbird. If a user were
tricked into opening a specially crafted website in a browsing context, an
attacker could potentially exploit these to cause a denial of service,
obtain sensitive information, bypass security restrictions, cross-site
tracing, or execute arbitrary code.(CVE-2024-5688, CVE-2024-5690,
CVE-2024-5696, CVE-2024-5700, CVE-2024-5702)
Luan Herrera discovered that Thunderbird did not properly validate the
X-Frame-Options header inside sandboxed iframe. An attacker could
potentially exploit this issue to bypass sandbox restrictions to open a new
window. (CVE-2024-5691)
Kirtikumar Anandrao Ramchandani discovered that Thunderbird did
Red Hat
Mozilla: Memory safety bugs fixed in Firefox 127, Firefox ESR 115.12, and Thunderbird 115.12
vendor_redhat·2024-06-11·CVSS 7.0
CVE-2024-5700 [HIGH] CWE-120 Mozilla: Memory safety bugs fixed in Firefox 127, Firefox ESR 115.12, and Thunderbird 115.12
Mozilla: Memory safety bugs fixed in Firefox 127, Firefox ESR 115.12, and Thunderbird 115.12
Memory safety bugs present in Firefox 126, Firefox ESR 115.11, and Thunderbird 115.11. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 127, Firefox ESR < 115.12, and Thunderbird < 115.12.
The Mozilla Foundation Security Advisory describes this flaw as:
Memory safety bugs present in Firefox 126, Firefox ESR 115.11, and Thunderbird 115.11. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code.
Statement: Red Hat Product Security rates the severity of t
Cisco
Cisco IOS XR Software SSH Privilege Escalation Vulnerability
vendor_cisco·2024-03-13·CVSS 7.8
CVE-2024-20320 [HIGH] CWE-266 Cisco IOS XR Software SSH Privilege Escalation Vulnerability
Cisco IOS XR Software SSH Privilege Escalation Vulnerability
A vulnerability in the SSH client feature of Cisco IOS XR Software for Cisco 8000 Series Routers and Cisco Network Convergence System (NCS) 540 Series and 5700 Series Routers could allow an authenticated, local attacker to elevate privileges on an affected device.
This vulnerability is due to insufficient validation of arguments that are included with the SSH client CLI command. An attacker with low-privileged access to an affected device could exploit this vulnerability by issuing a crafted SSH client command to the CLI. A successful exploit could allow the attacker to elevate privileges to root on the affected device.
Cisco has released software updates that address this vulnerability. There are no workarounds that address t
Debian
CVE-2024-5700: firefox - Memory safety bugs present in Firefox 126, Firefox ESR 115.11, and Thunderbird 1...
vendor_debian·2024·CVSS 7.0
CVE-2024-5700 [HIGH] CVE-2024-5700: firefox - Memory safety bugs present in Firefox 126, Firefox ESR 115.11, and Thunderbird 1...
Memory safety bugs present in Firefox 126, Firefox ESR 115.11, and Thunderbird 115.11. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 127, Firefox ESR < 115.12, and Thunderbird < 115.12.
Scope: local
sid: resolved (fixed in 127.0-1)
Mozilla
Mozilla Foundation Security Advisory 2024-26: CVE-2024-5700
vendor_mozilla·CVSS 7.0
CVE-2024-5700 [HIGH] Mozilla Foundation Security Advisory 2024-26: CVE-2024-5700
Mozilla Foundation Security Advisory 2024-26
CVE: CVE-2024-5700
Product: Firefox ESR
Impact: high
Fixed in: Firefox ESR 115.12
Mozilla
Mozilla Foundation Security Advisory 2024-28: CVE-2024-5700
vendor_mozilla·CVSS 7.0
CVE-2024-5700 [HIGH] Mozilla Foundation Security Advisory 2024-28: CVE-2024-5700
Mozilla Foundation Security Advisory 2024-28
CVE: CVE-2024-5700
Product: Thunderbird
Impact: high
Fixed in: Thunderbird 115.12
Mozilla
Mozilla Foundation Security Advisory 2024-25: CVE-2024-5700
vendor_mozilla·CVSS 7.0
CVE-2024-5700 [HIGH] Mozilla Foundation Security Advisory 2024-25: CVE-2024-5700
Mozilla Foundation Security Advisory 2024-25
CVE: CVE-2024-5700
Product: Firefox
Impact: high
Fixed in: Firefox 127
Cisco
Cisco IOS XR Software SSH Privilege Escalation Vulnerability
vendor_cisco·CVSS 3.1
CVE-2024-20320 Cisco IOS XR Software SSH Privilege Escalation Vulnerability
CVE-2024-20320: Cisco IOS XR Software SSH Privilege Escalation Vulnerability
A vulnerability in the SSH client feature of Cisco IOS XR Software for Cisco 8000 Series Routers and Cisco Network Convergence System (NCS) 540 Series and 5700 Series Routers could allow an authenticated, local attacker to elevate privileges on an affected device. This vulnerability is due to insufficient validation of arguments that are included with the SSH client CLI command. An attacker with low-privileged access to an affected device could exploit this vulnerability by issuing a crafted SSH client command to the CLI. A successful exploit could allow the attacker to elevate privileges to root on the affected device. Cisco has released software updates that address this vulnerability. There are no
CVSS: 3.1
CWE
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://bugzilla.mozilla.org/buglist.cgi?bug_id=1862809%2C1889355%2C1893388%2C1895123https://lists.debian.org/debian-lts-announce/2024/06/msg00000.htmlhttps://lists.debian.org/debian-lts-announce/2024/06/msg00010.htmlhttps://www.mozilla.org/security/advisories/mfsa2024-25/https://www.mozilla.org/security/advisories/mfsa2024-26/https://www.mozilla.org/security/advisories/mfsa2024-28/https://bugzilla.mozilla.org/buglist.cgi?bug_id=1862809%2C1889355%2C1893388%2C1895123https://lists.debian.org/debian-lts-announce/2024/06/msg00000.htmlhttps://lists.debian.org/debian-lts-announce/2024/06/msg00010.htmlhttps://www.mozilla.org/security/advisories/mfsa2024-25/https://www.mozilla.org/security/advisories/mfsa2024-26/https://www.mozilla.org/security/advisories/mfsa2024-28/
2024-06-11
Published