Show filters
1,460 Total Results
Displaying 471-480 of 1,460
Sort by:
Attacker Value
Unknown
CVE-2020-15652
Disclosure Date: August 10, 2020 (last updated February 21, 2025)
By observing the stack trace for JavaScript errors in web workers, it was possible to leak the result of a cross-origin redirect. This applied only to content that can be parsed as script. This vulnerability affects Firefox < 79, Firefox ESR < 68.11, Firefox ESR < 78.1, Thunderbird < 68.11, and Thunderbird < 78.1.
0
Attacker Value
Unknown
CVE-2020-15648
Disclosure Date: August 10, 2020 (last updated February 21, 2025)
Using object or embed tags, it was possible to frame other websites, even if they disallowed framing using the X-Frame-Options header. This vulnerability affects Thunderbird < 78 and Firefox < 78.0.2.
0
Attacker Value
Unknown
CVE-2020-15655
Disclosure Date: August 10, 2020 (last updated November 28, 2024)
A redirected HTTP request which is observed or modified through a web extension could bypass existing CORS checks, leading to potential disclosure of cross-origin information. This vulnerability affects Firefox ESR < 78.1, Firefox < 79, and Thunderbird < 78.1.
0
Attacker Value
Unknown
CVE-2020-15659
Disclosure Date: August 10, 2020 (last updated February 21, 2025)
Mozilla developers and community members reported memory safety bugs present in Firefox 78 and Firefox ESR 78.0. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 79, Firefox ESR < 68.11, Firefox ESR < 78.1, Thunderbird < 68.11, and Thunderbird < 78.1.
0
Attacker Value
Unknown
CVE-2020-12417
Disclosure Date: July 09, 2020 (last updated February 21, 2025)
Due to confusion about ValueTags on JavaScript Objects, an object may pass through the type barrier, resulting in memory corruption and a potentially exploitable crash. *Note: this issue only affects Firefox on ARM64 platforms.* This vulnerability affects Firefox ESR < 68.10, Firefox < 78, and Thunderbird < 68.10.0.
0
Attacker Value
Unknown
CVE-2020-12418
Disclosure Date: July 09, 2020 (last updated February 21, 2025)
Manipulating individual parts of a URL object could have caused an out-of-bounds read, leaking process memory to malicious JavaScript. This vulnerability affects Firefox ESR < 68.10, Firefox < 78, and Thunderbird < 68.10.0.
0
Attacker Value
Unknown
CVE-2020-12405
Disclosure Date: July 09, 2020 (last updated February 21, 2025)
When browsing a malicious page, a race condition in our SharedWorkerService could occur and lead to a potentially exploitable crash. This vulnerability affects Thunderbird < 68.9.0, Firefox < 77, and Firefox ESR < 68.9.
0
Attacker Value
Unknown
CVE-2020-12399
Disclosure Date: July 09, 2020 (last updated February 21, 2025)
NSS has shown timing differences when performing DSA signatures, which was exploitable and could eventually leak private keys. This vulnerability affects Thunderbird < 68.9.0, Firefox < 77, and Firefox ESR < 68.9.
0
Attacker Value
Unknown
CVE-2020-12419
Disclosure Date: July 09, 2020 (last updated February 21, 2025)
When processing callbacks that occurred during window flushing in the parent process, the associated window may die; causing a use-after-free condition. This could have led to memory corruption and a potentially exploitable crash. This vulnerability affects Firefox ESR < 68.10, Firefox < 78, and Thunderbird < 68.10.0.
0
Attacker Value
Unknown
CVE-2020-12421
Disclosure Date: July 09, 2020 (last updated February 21, 2025)
When performing add-on updates, certificate chains terminating in non-built-in-roots were rejected (even if they were legitimately added by an administrator.) This could have caused add-ons to become out-of-date silently without notification to the user. This vulnerability affects Firefox ESR < 68.10, Firefox < 78, and Thunderbird < 68.10.0.
0