Show filters
1,460 Total Results
Displaying 451-460 of 1,460
Sort by:
Attacker Value
Unknown
CVE-2020-26958
Disclosure Date: December 09, 2020 (last updated February 22, 2025)
Firefox did not block execution of scripts with incorrect MIME types when the response was intercepted and cached through a ServiceWorker. This could lead to a cross-site script inclusion vulnerability, or a Content Security Policy bypass. This vulnerability affects Firefox < 83, Firefox ESR < 78.5, and Thunderbird < 78.5.
0
Attacker Value
Unknown
CVE-2020-26950
Disclosure Date: December 09, 2020 (last updated February 22, 2025)
In certain circumstances, the MCallGetProperty opcode can be emitted with unmet assumptions resulting in an exploitable use-after-free condition. This vulnerability affects Firefox < 82.0.3, Firefox ESR < 78.4.1, and Thunderbird < 78.4.2.
0
Attacker Value
Unknown
CVE-2020-26960
Disclosure Date: December 09, 2020 (last updated February 22, 2025)
If the Compact() method was called on an nsTArray, the array could have been reallocated without updating other pointers, leading to a potential use-after-free and exploitable crash. This vulnerability affects Firefox < 83, Firefox ESR < 78.5, and Thunderbird < 78.5.
0
Attacker Value
Unknown
CVE-2020-26970
Disclosure Date: December 09, 2020 (last updated February 22, 2025)
When reading SMTP server status codes, Thunderbird writes an integer value to a position on the stack that is intended to contain just one byte. Depending on processor architecture and stack layout, this leads to stack corruption that may be exploitable. This vulnerability affects Thunderbird < 78.5.1.
0
Attacker Value
Unknown
CVE-2020-26959
Disclosure Date: December 09, 2020 (last updated February 22, 2025)
During browser shutdown, reference decrementing could have occured on a previously freed object, resulting in a use-after-free, memory corruption, and a potentially exploitable crash. This vulnerability affects Firefox < 83, Firefox ESR < 78.5, and Thunderbird < 78.5.
0
Attacker Value
Unknown
CVE-2020-15683
Disclosure Date: October 22, 2020 (last updated February 22, 2025)
Mozilla developers and community members reported memory safety bugs present in Firefox 81 and Firefox ESR 78.3. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox ESR < 78.4, Firefox < 82, and Thunderbird < 78.4.
0
Attacker Value
Unknown
CVE-2020-15646
Disclosure Date: October 08, 2020 (last updated November 28, 2024)
If an attacker intercepts Thunderbird's initial attempt to perform automatic account setup using the Microsoft Exchange autodiscovery mechanism, and the attacker sends a crafted response, then Thunderbird sends username and password over https to a server controlled by the attacker. This vulnerability affects Thunderbird < 68.10.0.
0
Attacker Value
Unknown
CVE-2020-15676
Disclosure Date: October 01, 2020 (last updated February 22, 2025)
Firefox sometimes ran the onload handler for SVG elements that the DOM sanitizer decided to remove, resulting in JavaScript being executed after pasting attacker-controlled data into a contenteditable element. This vulnerability affects Firefox < 81, Thunderbird < 78.3, and Firefox ESR < 78.3.
0
Attacker Value
Unknown
CVE-2020-15664
Disclosure Date: October 01, 2020 (last updated February 22, 2025)
By holding a reference to the eval() function from an about:blank window, a malicious webpage could have gained access to the InstallTrigger object which would allow them to prompt the user to install an extension. Combined with user confusion, this could result in an unintended or malicious extension being installed. This vulnerability affects Firefox < 80, Thunderbird < 78.2, Thunderbird < 68.12, Firefox ESR < 68.12, Firefox ESR < 78.2, and Firefox for Android < 80.
0
Attacker Value
Unknown
CVE-2020-15670
Disclosure Date: October 01, 2020 (last updated February 22, 2025)
Mozilla developers reported memory safety bugs present in Firefox for Android 79. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 80, Firefox ESR < 78.2, Thunderbird < 78.2, and Firefox for Android < 80.
0