|
195011
|
9.8 |
CRITICAL
Network
|
stockware
|
motor
|
Lack of authentication or validation in motor_load_more, motor_gallery_load_more, motor_quick_view and motor_project_quick_view AJAX handlers of the Motor WordPress theme before 3.1.0 allows an unaut…
|
-
|
CVE-2021-24375
|
2024-11-21 14:52 |
2021-07-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195012
|
7.5 |
HIGH
Network
|
fortinet
|
fortiauthenticator
|
Usage of hard-coded cryptographic keys to encrypt configuration files and debug logs in FortiAuthenticator versions before 6.3.0 may allow an attacker with access to the files or the CLI configuratio…
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2021-24005
|
2024-11-21 14:52 |
2021-07-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195013
|
8.8 |
HIGH
Network
|
mozilla
|
thunderbird firefox firefox_esr
|
When a user clicked on an FTP URL containing encoded newline characters (%0A and %0D), the newlines would have been interpreted as such and allowed arbitrary commands to be sent to the FTP server. Th…
|
CWE-74
Injection
|
CVE-2021-24002
|
2024-11-21 14:52 |
2021-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195014
|
4.3 |
MEDIUM
Network
|
mozilla
|
firefox
|
A compromised content process could have performed session history manipulations it should not have been able to due to testing infrastructure that was not restricted to testing-only configurations. …
|
CWE-668
Exposure of Resource to Wrong Sphere
|
CVE-2021-24001
|
2024-11-21 14:52 |
2021-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195015
|
3.1 |
LOW
Network
|
mozilla
|
firefox
|
A race condition with requestPointerLock() and setTimeout() could have resulted in a user interacting with one tab when they believed they were on a separate tab. In conjunction with certain elements…
|
CWE-362
Race Condition
|
CVE-2021-24000
|
2024-11-21 14:52 |
2021-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195016
|
8.8 |
HIGH
Network
|
mozilla
|
thunderbird firefox firefox_esr
|
If a Blob URL was loaded through some unusual user interaction, it could have been loaded by the System Principal and granted additional privileges that should not be granted to web content. This vul…
|
CWE-269 CWE-697
Improper Privilege Management Incorrect Comparison
|
CVE-2021-23999
|
2024-11-21 14:52 |
2021-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195017
|
6.5 |
MEDIUM
Network
|
mozilla
|
thunderbird firefox firefox_esr
|
Through complicated navigations with new windows, an HTTP page could have inherited a secure lock icon from an HTTPS page. This vulnerability affects Firefox ESR < 78.10, Thunderbird < 78.10, and Fir…
|
CWE-345
Insufficient Verification of Data Authenticity
|
CVE-2021-23998
|
2024-11-21 14:52 |
2021-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195018
|
8.8 |
HIGH
Network
|
mozilla
|
firefox
|
Due to unexpected data type conversions, a use-after-free could have occurred when interacting with the font cache. We presume that with enough effort this could have been exploited to run arbitrary …
|
CWE-681
Incorrect Conversion between Numeric Types
|
CVE-2021-23997
|
2024-11-21 14:52 |
2021-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195019
|
6.5 |
MEDIUM
Network
|
mozilla
|
firefox
|
By utilizing 3D CSS in conjunction with Javascript, content could have been rendered outside the webpage's viewport, resulting in a spoofing attack that could have been used for phishing or other att…
|
NVD-CWE-Other
|
CVE-2021-23996
|
2024-11-21 14:52 |
2021-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195020
|
8.8 |
HIGH
Network
|
mozilla
|
thunderbird firefox firefox_esr
|
When Responsive Design Mode was enabled, it used references to objects that were previously freed. We presume that with enough effort this could have been exploited to run arbitrary code. This vulner…
|
CWE-672
Operation on a Resource after Expiration or Release
|
CVE-2021-23995
|
2024-11-21 14:52 |
2021-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|