![]() This could have caused requests to be sent with some cookies missing. When the number of cookies per domain was exceeded in okie, the actual cookie jar sent to the host was no longer consistent with expected cookie jar state. #CVE-2023-4055: Cookie jar overflow caused unexpected cookie jar state Reporter Marco Squarcina Impact low Description When opening appref-ms files, Firefox did not warn the user that these files may contain malicious code. #CVE-2023-4054: Lack of warning when opening appref-ms files Reporter P Umar Farooq Impact moderate Description This could have led to user confusion and possible spoofing attacks. #CVE-2023-4053: Full screen notification obscured by external program Reporter P Umar Farooq Impact moderate DescriptionĪ website could have obscured the full screen notification by using a URL with a scheme handled by an external program, such as a mailto URL. This bug only affects Firefox on Windows. This could be combined with creation of a junction (a form of symbolic link) to allow arbitrary file deletion controlled by the non-privileged user. When uninstalling Firefox, any files in that directory would be recursively deleted with the permissions of the uninstalling user account. The Firefox updater created a directory writable by non-privileged users. #CVE-2023-4052: File deletion and privilege escalation through Firefox uninstaller Reporter ycdxsb Impact moderate Description #CVE-2023-4051: Full screen notification obscured by file open dialog Reporter Hafiizh Impact moderate DescriptionĪ website could have obscured the full screen notification by using the file open dialog. This resulted in a potentially exploitable crash which could have led to a sandbox escape. In some cases, an untrusted input stream was copied to a stack buffer without checking its size. #CVE-2023-4050: Stack buffer overflow in StorageManager Reporter Mark Brand Impact high Description These could have resulted in potentially exploitable use-after-free vulnerabilities. Race conditions in reference counting code were found through code inspection. #CVE-2023-4049: Fix potential race conditions when releasing platform objects Reporter Nika Layzell Impact high Description #CVE-2023-4048: Crash in DOMParser due to out-of-memory conditions Reporter Irvan Kurniawan Impact high DescriptionĪn out-of-bounds read could have led to an exploitable crash when parsing HTML with DOMParser in low memory situations. #CVE-2023-4047: Potential permissions request bypass via clickjacking Reporter Axel Chong Impact high DescriptionĪ bug in popup notifications delay calculation could have made it possible for an attacker to trick a user into granting permissions. This resulted in incorrect compilation and a potentially exploitable crash in the content process. In some circumstances, a stale value could have been used for a global variable in WASM JIT analysis. #CVE-2023-4046: Incorrect value used during WASM compilation Reporter Alexander Guryanov Impact high Description Offscreen Canvas did not properly track cross-origin tainting, which could have been used to access image data from another site in violation of same-origin policy. #CVE-2023-4045: Offscreen Canvas could have bypassed cross-origin restrictions Reporter Max Vlasov Impact high Description These add-ons can be indispensable tools for building an email client that will meet your specific needs.Mozilla Foundation Security Advisory 2023-29 Security Vulnerabilities fixed in Firefox 116 Announced AugImpact high Products Firefox Fixed in ![]() Mozilla Thunderbird will also permit almost unlimited additional features through the available Mozilla Add-Ons. It also utilizes enterprise and government-grade security features like digital signing, message encryption, S/MIME, support for certificates, and security devices. It will also allow you to select any that may sneak through manually. You will benefit from Thunderbird's junk mail filtering, which effectively analyzes all mail and identifies those with the highest probability of being junk mail. This email client provides many essential safety features for the organization and all your incoming and outgoing mail. It includes many native features, including quick message search, customizable views, and IMAP/POP and RSS support. Mozilla Thunderbird is designed to be a very safe, fast email client that's also easy to use. Mozilla Thunderbird for Windows, Linux, and Mac is a free cross-platform email application that's easy to set up and customize - and it's loaded with great features. ![]()
0 Comments
Leave a Reply. |
AuthorWrite something about yourself. No need to be fancy, just an overview. ArchivesCategories |