VDB

GCVE-110-MAGEIA-2024-349

GCVE-110-MAGEIA-2024-349
Advisory Published
Vulnetix · Advisory published November 9, 2024
Permission leak via embed or object elements. (CVE-2024-10458) Use-after-free in layout with accessibility. (CVE-2024-10459) Confusing display of origin for external protocol handler prompt. (CVE-2024-10460) XSS due to Content-Disposition being ignored in multipart/x-mixed-replace response. (CVE-2024-10461) Origin of permission prompt could be spoofed by long URL. (CVE-2024-10462) Cross origin video frame leak. (CVE-2024-10463) History interface could have been used to cause a Denial of Service condition in the browser. (CVE-2024-10464) Clipboard "paste" button persisted across tabs. (CVE-2024-10465) DOM push subscription message could hang Firefox. (CVE-2024-10466) Memory safety bugs fixed in Firefox 132, Thunderbird 132, Firefox ESR 128.4, and Thunderbird 128.4. (CVE-2024-10467)

Affected Products

VendorProductVersionsPlatforms
Mageiafirefox0 (affected), 128.4.0-1.mga9 (unaffected)
Mageiafirefox-l10n0 (affected), 128.4.0-1.mga9 (unaffected)
Mageianss0 (affected), 3.106.0-1.mga9 (unaffected)
Mageiarust0 (affected), 1.76.0-3.mga9 (unaffected)
Mageianspr0 (affected), 4.36-1.mga9 (unaffected)

Browse GCVE Records

74,265 records in the GCVE database · Updated July 22, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›