Kaspersky ID:
KLA68933
Fecha de detección:
06/13/2024
Actualizado:
01/28/2026

Descripción

Multiple vulnerabilities were found in Mozilla Thunderbird. Malicious users can exploit these vulnerabilities to execute arbitrary code, cause denial of service, perform cross-site scripting attack, bypass security restrictions, spoof user interface, obtain sensitive information.

Below is a complete list of vulnerabilities:

  1. Use after free vulnerability in networking can be exploited to cause denial of service or execute arbitrary code.
  2. Use after free vulnerability in JavaScript object transplant can be exploited to cause denial of service or execute arbitrary code.
  3. Сorrupt memory leading vulnerability in Text Fragments can be exploited to a potentially exploitable crash.
  4. Heap buffer overflow vulnerability can be exploited to cause denial of service.
  5. Security vulnerability can be exploited to bypass security restrictions.
  6. Security vulnerability when using the ‘Save As’ functionality can be exploited to bypass security restrictions.
  7. Information disclosure vulnerability can be exploited to obtain sensitive information.
  8. Information disclosure vulnerability in Offscreen Canvas can be exploited to obtain sensitive information.

Notas informativas originales

Explotación

Public exploits exist for this vulnerability.

Productos relacionados

Lista CVE

  • CVE-2024-5692
    high
  • CVE-2024-5702
    critical
  • CVE-2024-5688
    critical
  • CVE-2024-5700
    high
  • CVE-2024-5693
    high
  • CVE-2024-5690
    warning
  • CVE-2024-5691
    warning
  • CVE-2024-5696
    critical

Leer más

Conozca las estadísticas de las vulnerabilidades que se propagan en su región statistics.securelist.com

¿Has encontrado algún error en la descripción de esta vulnerabilidad? ¡Háznoslo saber!
Kaspersky Next:
ciberseguridad redefinida
Leer más
Nuevo Kaspersky
¡Su vida digital merece una protección completa!
Leer más
Do you want to save your changes?
Your message has been sent successfully.