CVE-2024-6992
published 2024CVE-2024-6992: bookworm: resolved (fixed in 127.0.6533.88-1~deb12u1) bullseye: open forky: resolved (fixed in 127.0.6533.88-1) sid: resolved (fixed in 127.0.6533.88-1)…
critical9.8
bookworm: resolved (fixed in 127.0.6533.88-1~deb12u1)
bullseye: open
forky: resolved (fixed in 127.0.6533.88-1)
sid: resolved (fixed in 127.0.6533.88-1)
trixie: resolved (fixed in 127.0.6533.88-1)
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | chromium | < chromium 127.0.6533.88-1~deb12u1 (bookworm) | chromium 127.0.6533.88-1~deb12u1 (bookworm) |
| mozilla | firefox | >= 0 < 130.0.1+build1-0ubuntu0.20.04.1 | 130.0.1+build1-0ubuntu0.20.04.1 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2024-6992: chromium
vendor_debian·2024
CVE-2024-6992 CVE-2024-6992: chromium
bookworm: resolved (fixed in 127.0.6533.88-1~deb12u1)
bullseye: open
forky: resolved (fixed in 127.0.6533.88-1)
sid: resolved (fixed in 127.0.6533.88-1)
trixie: resolved (fixed in 127.0.6533.88-1)
OSV
firefox regressions
osv·2024-09-23·CVSS 9.8
CVE-2024-8382 firefox regressions
firefox regressions
USN-6992-1 fixed vulnerabilities in Firefox. The update introduced
several minor regressions. This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
Multiple security issues were discovered in Firefox. If a user were
tricked into opening a specially crafted website, an attacker could
potentially exploit these to cause a denial of service, obtain sensitive
information across domains, or execute arbitrary code. (CVE-2024-8382,
CVE-2024-8383, CVE-2024-8386, CVE-2024-8387, CVE-2024-8389)
Nils Bars discovered that Firefox contained a type confusion vulnerability
when performing certain property name lookups. An attacker could
potentially exploit this issue to cause a denial of service, or execute
arbitrary code. (CVE-2024-8381)
It
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2024
Published