|
210421
|
6.5 |
MEDIUM
Network
|
mozilla
|
firefox
|
When a malicious application installed on the user's device broadcast an Intent to Firefox for Android, arbitrary headers could have been specified, leading to attacks such as abusing ambient authori…
|
NVD-CWE-noinfo
|
CVE-2020-26975
|
2024-11-21 14:20 |
2021-01-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210422
|
8.8 |
HIGH
Network
|
mozilla
|
firefox_esr thunderbird firefox
|
When flex-basis was used on a table wrapper, a StyleGenericFlexBasis object could have been incorrectly cast to the wrong type. This resulted in a heap user-after-free, memory corruption, and a poten…
|
CWE-787
Out-of-bounds Write
|
CVE-2020-26974
|
2024-11-21 14:20 |
2021-01-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210423
|
8.8 |
HIGH
Network
|
mozilla
|
firefox_esr thunderbird firefox
|
Certain input to the CSS Sanitizer confused it, resulting in incorrect components being removed. This could have been used as a sanitizer bypass. This vulnerability affects Firefox < 84, Thunderbird …
|
NVD-CWE-noinfo
|
CVE-2020-26973
|
2024-11-21 14:20 |
2021-01-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210424
|
9.8 |
CRITICAL
Network
|
mozilla
|
firefox
|
The lifecycle of IPC Actors allows managed actors to outlive their manager actors; and the former must ensure that they are not attempting to use a dead actor they have a reference to. Such a check w…
|
CWE-416
Use After Free
|
CVE-2020-26972
|
2024-11-21 14:20 |
2021-01-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210425
|
8.8 |
HIGH
Network
|
mozilla
|
firefox_esr thunderbird firefox
|
Certain blit values provided by the user were not properly constrained leading to a heap buffer overflow on some video drivers. This vulnerability affects Firefox < 84, Thunderbird < 78.6, and Firefo…
|
CWE-787
Out-of-bounds Write
|
CVE-2020-26971
|
2024-11-21 14:20 |
2021-01-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210426
|
6.1 |
MEDIUM
Network
|
formstone
|
formstone
|
Formstone <=1.4.16 is vulnerable to a Reflected Cross-Site Scripting (XSS) vulnerability caused by improper validation of user supplied input in the upload-target.php and upload-chunked.php files. A …
|
CWE-79
Cross-site Scripting
|
CVE-2020-26768
|
2024-11-21 14:20 |
2021-01-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210427
|
5.3 |
MEDIUM
Network
|
redlion
|
crimson
|
An attacker could send a specially crafted message to Crimson 3.1 (Build versions prior to 3119.001) that could leak arbitrary memory locations.
|
CWE-404
Improper Resource Shutdown or Release
|
CVE-2020-27283
|
2024-11-21 14:20 |
2021-01-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210428
|
7.5 |
HIGH
Network
|
redlion
|
crimson
|
A NULL pointer deference vulnerability has been identified in the protocol converter. An attacker could send a specially crafted packet that could reboot the device running Crimson 3.1 (Build version…
|
CWE-476
NULL Pointer Dereference
|
CVE-2020-27279
|
2024-11-21 14:20 |
2021-01-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210429
|
9.1 |
CRITICAL
Network
|
redlion
|
crimson
|
The default configuration of Crimson 3.1 (Build versions prior to 3119.001) allows a user to be able to read and modify the database without authentication.
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2020-27285
|
2024-11-21 14:20 |
2021-01-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210430
|
9.8 |
CRITICAL
Network
|
clickhouse-driver_project
|
clickhouse-driver
|
clickhouse-driver before 0.1.5 allows a malicious clickhouse server to trigger a crash or execute arbitrary code (on a database client) via a crafted server response, due to a buffer overflow.
|
CWE-120
Classic Buffer Overflow
|
CVE-2020-26759
|
2024-11-21 14:20 |
2021-01-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|