Mozilla Firefox is a standalone web browser, designed for standards compliance and performance. Its functionality can be enhanced via a plethora of extensions.
Security Fix(es):
An attacker could, via a specially crafted multipart response, execute arbitrary JavaScript under the resource://pdf.js
origin. This could allow them to access cross-origin PDF content. This access is limited to "same site" documents by the Site Isolation feature on desktop clients, but full cross-origin access is possible on Android versions. This vulnerability affects Firefox < 131, Firefox ESR < 128.3, Firefox ESR < 115.16, Thunderbird < 128.3, and Thunderbird < 131.(CVE-2024-9393)
An attacker could, via a specially crafted multipart response, execute arbitrary JavaScript under the resource://devtools
origin. This could allow them to access cross-origin JSON content. This access is limited to "same site" documents by the Site Isolation feature on desktop clients, but full cross-origin access is possible on Android versions. This vulnerability affects Firefox < 131, Firefox ESR < 128.3, Firefox ESR < 115.16, Thunderbird < 128.3, and Thunderbird < 131.(CVE-2024-9394)
A missing delay in directory upload UI could have made it possible for an attacker to trick a user into granting permission via clickjacking. This vulnerability affects Firefox < 131, Firefox ESR < 128.3, Thunderbird < 128.3, and Thunderbird < 131.(CVE-2024-9397)
A website configured to initiate a specially crafted WebTransport session could crash the Firefox process leading to a denial of service condition. This vulnerability affects Firefox < 131, Firefox ESR < 128.3, Thunderbird < 128.3, and Thunderbird < 131.(CVE-2024-9399)
{ "severity": "High" }
{ "x86_64": [ "firefox-128.3.0-2.oe2403.x86_64.rpm", "firefox-debuginfo-128.3.0-2.oe2403.x86_64.rpm", "firefox-debugsource-128.3.0-2.oe2403.x86_64.rpm" ], "aarch64": [ "firefox-128.3.0-2.oe2403.aarch64.rpm", "firefox-debuginfo-128.3.0-2.oe2403.aarch64.rpm", "firefox-debugsource-128.3.0-2.oe2403.aarch64.rpm" ], "src": [ "firefox-128.3.0-2.oe2403.src.rpm" ] }