|
196231
|
7.8 |
HIGH
Local
|
mcafee
|
application_and_change_control
|
DLL Side Loading vulnerability in the installer for McAfee Application and Change Control (MACC) prior to 8.3 allows local users to execute arbitrary code via execution from a compromised folder.
|
CWE-426
Untrusted Search Path
|
CVE-2020-7260
|
2024-11-21 14:36 |
2020-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196232
|
6.5 |
MEDIUM
Network
|
moxa
|
mds-g516e_firmware
|
In Moxa EDS-G516E Series firmware, Version 5.2 or lower, some of the parameters in the setting pages do not ensure text is the correct size for its buffer.
|
CWE-120
Classic Buffer Overflow
|
CVE-2020-6999
|
2024-11-21 14:36 |
2020-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196233
|
9.8 |
CRITICAL
Network
|
mozilla
|
firefox
|
Mozilla developers reported memory safety and script safety bugs present in Firefox 73. Some of these bugs showed evidence of memory corruption or escalation of privilege and we presume that with eno…
|
CWE-787
Out-of-bounds Write
|
CVE-2020-6815
|
2024-11-21 14:36 |
2020-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196234
|
9.8 |
CRITICAL
Network
|
mozilla canonical
|
firefox_esr thunderbird firefox ubuntu_linux
|
Mozilla developers reported memory safety bugs present in Firefox and Thunderbird 68.5. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these co…
|
CWE-787
Out-of-bounds Write
|
CVE-2020-6814
|
2024-11-21 14:36 |
2020-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196235
|
5.3 |
MEDIUM
Network
|
mozilla
|
firefox
|
When protecting CSS blocks with the nonce feature of Content Security Policy, the @import statement in the CSS block could allow an attacker to inject arbitrary styles, bypassing the intent of the Co…
|
NVD-CWE-Other
|
CVE-2020-6813
|
2024-11-21 14:36 |
2020-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196236
|
5.3 |
MEDIUM
Network
|
mozilla canonical
|
firefox_esr thunderbird firefox ubuntu_linux
|
The first time AirPods are connected to an iPhone, they become named after the user's name by default (e.g. Jane Doe's AirPods.) Websites with camera or microphone permission are able to enumerate de…
|
CWE-200
Information Exposure
|
CVE-2020-6812
|
2024-11-21 14:36 |
2020-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196237
|
8.8 |
HIGH
Network
|
mozilla canonical
|
firefox_esr thunderbird firefox ubuntu_linux
|
The 'Copy as cURL' feature of Devtools' network tab did not properly escape the HTTP method of a request, which can be controlled by the website. If a user used the 'Copy as Curl' feature and pasted …
|
CWE-77
Command Injection
|
CVE-2020-6811
|
2024-11-21 14:36 |
2020-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196238
|
4.3 |
MEDIUM
Network
|
mozilla
|
firefox
|
After a website had entered fullscreen mode, it could have used a previously opened popup to obscure the notification that indicates the browser is in fullscreen mode. Combined with spoofing the brow…
|
CWE-290
Authentication Bypass by Spoofing
|
CVE-2020-6810
|
2024-11-21 14:36 |
2020-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196239
|
7.5 |
HIGH
Network
|
mozilla
|
firefox
|
When a Web Extension had the all-urls permission and made a fetch request with a mode set to 'same-origin', it was possible for the Web Extension to read local files. This vulnerability affects Firef…
|
NVD-CWE-noinfo
|
CVE-2020-6809
|
2024-11-21 14:36 |
2020-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196240
|
6.5 |
MEDIUM
Network
|
mozilla
|
firefox
|
When a JavaScript URL (javascript:) is evaluated and the result is a string, this string is parsed to create an HTML document, which is then presented. Previously, this document's URL (as reported by…
|
CWE-290
Authentication Bypass by Spoofing
|
CVE-2020-6808
|
2024-11-21 14:36 |
2020-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|