|
196671
|
5.3 |
MEDIUM
Network
|
mozilla
|
firefox
|
When protecting CSS blocks with the nonce feature of Content Security Policy, the @import statement in the CSS block could allow an attacker to inject arbitrary styles, bypassing the intent of the Co…
|
NVD-CWE-Other
|
CVE-2020-6813
|
2024-11-21 14:36 |
2020-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196672
|
5.3 |
MEDIUM
Network
|
mozilla canonical
|
firefox_esr thunderbird firefox ubuntu_linux
|
The first time AirPods are connected to an iPhone, they become named after the user's name by default (e.g. Jane Doe's AirPods.) Websites with camera or microphone permission are able to enumerate de…
|
CWE-200
Information Exposure
|
CVE-2020-6812
|
2024-11-21 14:36 |
2020-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196673
|
8.8 |
HIGH
Network
|
mozilla canonical
|
firefox_esr thunderbird firefox ubuntu_linux
|
The 'Copy as cURL' feature of Devtools' network tab did not properly escape the HTTP method of a request, which can be controlled by the website. If a user used the 'Copy as Curl' feature and pasted …
|
CWE-77
Command Injection
|
CVE-2020-6811
|
2024-11-21 14:36 |
2020-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196674
|
4.3 |
MEDIUM
Network
|
mozilla
|
firefox
|
After a website had entered fullscreen mode, it could have used a previously opened popup to obscure the notification that indicates the browser is in fullscreen mode. Combined with spoofing the brow…
|
CWE-290
Authentication Bypass by Spoofing
|
CVE-2020-6810
|
2024-11-21 14:36 |
2020-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196675
|
7.5 |
HIGH
Network
|
mozilla
|
firefox
|
When a Web Extension had the all-urls permission and made a fetch request with a mode set to 'same-origin', it was possible for the Web Extension to read local files. This vulnerability affects Firef…
|
NVD-CWE-noinfo
|
CVE-2020-6809
|
2024-11-21 14:36 |
2020-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196676
|
6.5 |
MEDIUM
Network
|
mozilla
|
firefox
|
When a JavaScript URL (javascript:) is evaluated and the result is a string, this string is parsed to create an HTML document, which is then presented. Previously, this document's URL (as reported by…
|
CWE-290
Authentication Bypass by Spoofing
|
CVE-2020-6808
|
2024-11-21 14:36 |
2020-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196677
|
8.8 |
HIGH
Network
|
mozilla canonical
|
firefox_esr thunderbird firefox ubuntu_linux
|
When a device was changed while a stream was about to be destroyed, the <code>stream-reinit</code> task may have been executed after the stream was destroyed, causing a use-after-free and a potential…
|
CWE-416
Use After Free
|
CVE-2020-6807
|
2024-11-21 14:36 |
2020-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196678
|
8.8 |
HIGH
Network
|
mozilla canonical
|
firefox_esr thunderbird firefox ubuntu_linux
|
By carefully crafting promise resolutions, it was possible to cause an out-of-bounds read off the end of an array resized during script execution. This could have led to memory corruption and a poten…
|
CWE-125
Out-of-bounds Read
|
CVE-2020-6806
|
2024-11-21 14:36 |
2020-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196679
|
8.8 |
HIGH
Network
|
mozilla canonical
|
firefox_esr thunderbird firefox ubuntu_linux
|
When removing data about an origin whose tab was recently closed, a use-after-free could occur in the Quota manager, resulting in a potentially exploitable crash. This vulnerability affects Thunderbi…
|
CWE-416
Use After Free
|
CVE-2020-6805
|
2024-11-21 14:36 |
2020-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196680
|
6.1 |
MEDIUM
Network
|
mozilla fedoraproject
|
bleach fedora
|
In Mozilla Bleach before 3.12, a mutation XSS in bleach.clean when RCDATA and either svg or math tags are whitelisted and the keyword argument strip=False.
|
CWE-79
Cross-site Scripting
|
CVE-2020-6816
|
2024-11-21 14:36 |
2020-03-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|