|
2731
|
4.0 |
MEDIUM
Local
|
mozilla
|
firefox thunderbird
|
When using Alt-Svc, ALPN did not properly validate certificates when the original server is redirecting to an insecure site. This vulnerability was fixed in Firefox 134, Firefox ESR 128.6, Thunderbir…
|
CWE-295
Improper Certificate Validation
|
CVE-2025-0239
|
2026-04-14 00:16 |
2025-01-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2732
|
4.0 |
MEDIUM
Local
|
mozilla
|
firefox thunderbird
|
Al utilizar Alt-Svc, ALPN no validó correctamente los certificados cuando el servidor original redireccionaba a un sitio inseguro. Esta vulnerabilidad afecta a Firefox < 134 y Firefox ESR < 128…
|
CWE-295
Improper Certificate Validation
|
CVE-2025-0239
|
2026-04-14 00:16 |
2025-01-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2733
|
5.3 |
MEDIUM
Network
|
mozilla
|
firefox thunderbird
|
Assuming a controlled failed memory allocation, an attacker could have caused a use-after-free, leading to a potentially exploitable crash. This vulnerability was fixed in Firefox 134, Firefox ESR 12…
|
CWE-416
Use After Free
|
CVE-2025-0238
|
2026-04-14 00:16 |
2025-01-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2734
|
5.3 |
MEDIUM
Network
|
mozilla
|
firefox thunderbird
|
Suponiendo que se haya producido una asignación de memoria fallida y controlada, un atacante podría haber provocado un error de use-after-free, lo que habría provocado un bloqueo potencialmente explo…
|
CWE-416
Use After Free
|
CVE-2025-0238
|
2026-04-14 00:16 |
2025-01-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2735
|
5.4 |
MEDIUM
Network
|
mozilla
|
firefox thunderbird
|
The WebChannel API, which is used to transport various information across processes, did not check the sending principal but rather accepted the principal being sent. This could have led to privilege…
|
CWE-863
Incorrect Authorization
|
CVE-2025-0237
|
2026-04-14 00:16 |
2025-01-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2736
|
5.4 |
MEDIUM
Network
|
mozilla
|
firefox thunderbird
|
La WebChannel API, que se utiliza para transportar información diversa entre procesos, no comprobó el principal de envío, sino que aceptó el principal enviado. Esto podría haber provocado ataques de …
|
CWE-863
Incorrect Authorization
|
CVE-2025-0237
|
2026-04-14 00:16 |
2025-01-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2737
|
6.1 |
MEDIUM
Network
|
jquery drupal debian fedoraproject oracle netapp opensuse tenable
|
jquery drupal debian_linux fedora agile_product_lifecycle_management_for_process application_testing_suite banking_digital_experience blockchain_platform communications_applic…
|
In jQuery starting with 1.12.0 and before 3.5.0, passing HTML from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append(), and others) may…
|
CWE-79
Cross-site Scripting
|
CVE-2020-11022
|
2026-04-14 00:16 |
2020-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2738
|
6.1 |
MEDIUM
Network
|
jquery drupal debian fedoraproject oracle netapp opensuse tenable
|
jquery drupal debian_linux fedora agile_product_lifecycle_management_for_process application_testing_suite banking_digital_experience blockchain_platform communications_applic…
|
En las versiones de jQuery mayores o iguales a 1.2 y anteriores a la versión 3.5.0, se puede ejecutar HTML desde fuentes no seguras, incluso después de desinfectarlo, a uno de los métodos de manipula…
|
CWE-79
Cross-site Scripting
|
CVE-2020-11022
|
2026-04-14 00:16 |
2020-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2739
|
5.3 |
MEDIUM
Network
|
freescout
|
freescout
|
FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.211, checkIpByMask() in app/Misc/Helper.php checks whether the input IP contains a / character.…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-34443
|
2026-04-14 00:14 |
2026-04-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2740
|
4.4 |
MEDIUM
Local
|
anthropic
|
claude_sdk_for_python
|
The Claude SDK for Python provides access to the Claude API from Python applications. From version 0.86.0 to before version 0.87.0, the local filesystem memory tool in the Anthropic Python SDK create…
|
CWE-276 CWE-732
Incorrect Default Permissions Incorrect Permission Assignment for Critical Resource
|
CVE-2026-34450
|
2026-04-14 00:10 |
2026-04-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|