|
210061
|
6.5 |
MEDIUM
Network
|
mozilla canonical
|
thunderbird firefox_esr firefox ubuntu_linux
|
The code for downloading files did not properly take care of special characters, which led to an attacker being able to cut off the file ending at an earlier position, leading to a different file typ…
|
CWE-754
Improper Check for Unusual or Exceptional Conditions
|
CVE-2020-15658
|
2024-11-21 14:05 |
2020-08-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210062
|
7.8 |
HIGH
Local
|
mozilla
|
firefox firefox_esr thunderbird
|
Firefox could be made to load attacker-supplied DLL files from the installation directory. This required an attacker that is already capable of placing files in the installation directory. *Note: Thi…
|
CWE-427
Uncontrolled Search Path Element
|
CVE-2020-15657
|
2024-11-21 14:05 |
2020-08-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210063
|
8.8 |
HIGH
Network
|
mozilla opensuse canonical
|
thunderbird firefox_esr firefox leap ubuntu_linux
|
JIT optimizations involving the Javascript arguments object could confuse later optimizations. This risk was already mitigated by various precautions in the code, resulting in this bug rated at only …
|
CWE-843
Type Confusion
|
CVE-2020-15656
|
2024-11-21 14:05 |
2020-08-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210064
|
6.5 |
MEDIUM
Network
|
mozilla opensuse canonical
|
thunderbird firefox_esr firefox leap ubuntu_linux
|
A redirected HTTP request which is observed or modified through a web extension could bypass existing CORS checks, leading to potential disclosure of cross-origin information. This vulnerability affe…
|
NVD-CWE-noinfo
|
CVE-2020-15655
|
2024-11-21 14:05 |
2020-08-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210065
|
6.5 |
MEDIUM
Network
|
mozilla canonical
|
thunderbird firefox_esr firefox ubuntu_linux
|
When in an endless loop, a website specifying a custom cursor using CSS could make it look like the user is interacting with the user interface, when they are not. This could lead to a perceived brok…
|
CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')
|
CVE-2020-15654
|
2024-11-21 14:05 |
2020-08-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210066
|
6.5 |
MEDIUM
Network
|
mozilla canonical
|
thunderbird firefox_esr firefox ubuntu_linux
|
An iframe sandbox element with the allow-popups flag could be bypassed when using noopener links. This could have led to security issues for websites relying on sandbox configurations that allowed po…
|
NVD-CWE-Other
|
CVE-2020-15653
|
2024-11-21 14:05 |
2020-08-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210067
|
6.5 |
MEDIUM
Network
|
mozilla canonical
|
firefox firefox_esr thunderbird ubuntu_linux
|
By observing the stack trace for JavaScript errors in web workers, it was possible to leak the result of a cross-origin redirect. This applied only to content that can be parsed as script. This vulne…
|
CWE-346
Origin Validation Error
|
CVE-2020-15652
|
2024-11-21 14:05 |
2020-08-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210068
|
4.3 |
MEDIUM
Network
|
mozilla
|
firefox
|
A unicode RTL order character in the downloaded file name can be used to change the file's name during the download UI flow to change the file extension. This vulnerability affects Firefox for iOS < …
|
NVD-CWE-noinfo
|
CVE-2020-15651
|
2024-11-21 14:05 |
2020-08-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210069
|
5.5 |
MEDIUM
Local
|
mozilla
|
firefox_esr
|
Given an installed malicious file picker application, an attacker was able to overwrite local files and thus overwrite Firefox settings (but not access the previous profile). *Note: This issue only a…
|
NVD-CWE-noinfo
|
CVE-2020-15650
|
2024-11-21 14:05 |
2020-08-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210070
|
5.5 |
MEDIUM
Local
|
mozilla
|
firefox_esr
|
Given an installed malicious file picker application, an attacker was able to steal and upload local files of their choosing, regardless of the actually files picked. *Note: This issue only affected …
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-15649
|
2024-11-21 14:05 |
2020-08-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|