|
210291
|
8.8 |
HIGH
Network
|
mozilla canonical
|
thunderbird firefox firefox_esr ubuntu_linux
|
Mozilla Developer Iain Ireland discovered a missing type check during unboxed objects removal, resulting in a crash. We presume that with enough effort that it could be exploited to run arbitrary cod…
|
CWE-345
Insufficient Verification of Data Authenticity
|
CVE-2020-12406
|
2024-11-21 13:59 |
2020-07-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210292
|
5.3 |
MEDIUM
Network
|
mozilla canonical
|
thunderbird firefox firefox_esr ubuntu_linux
|
When browsing a malicious page, a race condition in our SharedWorkerService could occur and lead to a potentially exploitable crash. This vulnerability affects Thunderbird < 68.9.0, Firefox < 77, and…
|
CWE-362 CWE-416
Race Condition Use After Free
|
CVE-2020-12405
|
2024-11-21 13:59 |
2020-07-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210293
|
4.3 |
MEDIUM
Network
|
mozilla
|
firefox
|
For native-to-JS bridging the app requires a unique token to be passed that ensures non-app code can't call the bridging functions. That token could leak when used for downloading files. This vulnera…
|
CWE-79
Cross-site Scripting
|
CVE-2020-12404
|
2024-11-21 13:59 |
2020-07-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210294
|
4.4 |
MEDIUM
Local
|
mozilla opensuse fedoraproject debian
|
firefox leap fedora debian_linux
|
During RSA key generation, bignum implementations used a variation of the Binary Extended Euclidean Algorithm which entailed significantly input-dependent flow. This allowed an attacker able to perfo…
|
CWE-203
Information Exposure Through Discrepancy
|
CVE-2020-12402
|
2024-11-21 13:59 |
2020-07-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210295
|
4.4 |
MEDIUM
Local
|
mozilla debian
|
thunderbird firefox firefox_esr debian_linux
|
NSS has shown timing differences when performing DSA signatures, which was exploitable and could eventually leak private keys. This vulnerability affects Thunderbird < 68.9.0, Firefox < 77, and Firef…
|
CWE-203
Information Exposure Through Discrepancy
|
CVE-2020-12399
|
2024-11-21 13:59 |
2020-07-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210296
|
7.5 |
HIGH
Network
|
mozilla canonical
|
thunderbird ubuntu_linux
|
If Thunderbird is configured to use STARTTLS for an IMAP server, and the server sends a PREAUTH response, then Thunderbird will continue with an unencrypted connection, causing email data to be sent …
|
CWE-319
Cleartext Transmission of Sensitive Information
|
CVE-2020-12398
|
2024-11-21 13:59 |
2020-07-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210297
|
6.5 |
MEDIUM
Network
|
mozilla opensuse
|
firefox leap
|
When constructing a permission prompt for WebRTC, a URI was supplied from the content process. This URI was untrusted, and could have been the URI of an origin that was previously granted permission;…
|
CWE-276
Incorrect Default Permissions
|
CVE-2020-12424
|
2024-11-21 13:59 |
2020-07-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210298
|
7.5 |
HIGH
Network
|
apache oracle
|
camel enterprise_repository enterprise_manager_base_platform communications_diameter_signaling_router
|
Server-Side Template Injection and arbitrary file disclosure on Camel templating components
|
CWE-74
Injection
|
CVE-2020-11994
|
2024-11-21 13:59 |
2020-07-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210299
|
8.1 |
HIGH
Network
|
ledger
|
ledger_live
|
Ledger Live before 2.7.0 does not handle Bitcoin's Replace-By-Fee (RBF). It increases the user's balance with the value of an unconfirmed transaction as soon as it is received (before the transaction…
|
CWE-345
Insufficient Verification of Data Authenticity
|
CVE-2020-12119
|
2024-11-21 13:59 |
2020-07-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210300
|
7.8 |
HIGH
Local
|
phoenixcontact
|
pc_worx pc_worx_express
|
mwe file parsing in Phoenix Contact PC Worx and PC Worx Express version 1.87 and earlier is vulnerable to out-of-bounds read remote code execution. Manipulated PC Worx projects could lead to a remote…
|
CWE-125
Out-of-bounds Read
|
CVE-2020-12498
|
2024-11-21 13:59 |
2020-07-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|