|
209911
|
10.0 |
CRITICAL
Network
|
mozilla
|
firefox firefox_esr
|
The Firefox content processes did not sufficiently lockdown access control which could result in a sandbox escape. *Note: this issue only affects Firefox on Windows operating systems.*. This vulnerab…
|
CWE-20
Improper Input Validation
|
CVE-2020-12389
|
2024-11-21 13:59 |
2020-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209912
|
10.0 |
CRITICAL
Network
|
mozilla
|
firefox firefox_esr
|
The Firefox content processes did not sufficiently lockdown access control which could result in a sandbox escape. *Note: this issue only affects Firefox on Windows operating systems.*. This vulnerab…
|
CWE-20
Improper Input Validation
|
CVE-2020-12388
|
2024-11-21 13:59 |
2020-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209913
|
8.1 |
HIGH
Network
|
mozilla
|
thunderbird firefox firefox_esr
|
A race condition when running shutdown code for Web Worker led to a use-after-free vulnerability. This resulted in a potentially exploitable crash. This vulnerability affects Firefox ESR < 68.8, Fire…
|
CWE-362 CWE-416
Race Condition Use After Free
|
CVE-2020-12387
|
2024-11-21 13:59 |
2020-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209914
|
9.8 |
CRITICAL
Network
|
mozilla
|
firefox
|
Mozilla developers and community members reported memory safety bugs present in Firefox 75. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of thes…
|
CWE-787
Out-of-bounds Write
|
CVE-2020-12396
|
2024-11-21 13:59 |
2020-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209915
|
9.8 |
CRITICAL
Network
|
mozilla canonical
|
thunderbird firefox firefox_esr ubuntu_linux
|
Mozilla developers and community members reported memory safety bugs present in Firefox 75 and Firefox ESR 68.7. Some of these bugs showed evidence of memory corruption and we presume that with enoug…
|
CWE-787
Out-of-bounds Write
|
CVE-2020-12395
|
2024-11-21 13:59 |
2020-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209916
|
3.3 |
LOW
Local
|
mozilla
|
firefox
|
A logic flaw in our location bar implementation could have allowed a local attacker to spoof the current location by selecting a different origin and removing focus from the input element. This vulne…
|
NVD-CWE-noinfo
|
CVE-2020-12394
|
2024-11-21 13:59 |
2020-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209917
|
7.8 |
HIGH
Local
|
mozilla
|
firefox firefox_esr thunderbird
|
The 'Copy as cURL' feature of Devtools' network tab did not properly escape the HTTP method of a request, which can be controlled by the website. If a user used the 'Copy as cURL' feature and pasted …
|
CWE-78
OS Command
|
CVE-2020-12393
|
2024-11-21 13:59 |
2020-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209918
|
4.3 |
MEDIUM
Network
|
mozilla canonical
|
thunderbird ubuntu_linux
|
By encoding Unicode whitespace characters within the From email header, an attacker can spoof the sender email address that Thunderbird displays. This vulnerability affects Thunderbird < 68.8.0.
|
CWE-346
Origin Validation Error
|
CVE-2020-12397
|
2024-11-21 13:59 |
2020-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209919
|
6.6 |
MEDIUM
Local
|
splashtop
|
software_updater streamer
|
A Windows privilege change issue was discovered in Splashtop Software Updater before 1.5.6.16. Insecure permissions on the configuration file and named pipe allow for local privilege escalation to NT…
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2020-12431
|
2024-11-21 13:59 |
2020-05-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209920
|
8.8 |
HIGH
Local
|
unisys
|
algol_compiler
|
Unisys ALGOL Compiler 58.1 before 58.1a.15, 59.1 before 59.1a.9, and 60.0 before 60.0a.5 can emit invalid code sequences under rare circumstances related to syntax. The resulting code could, for exam…
|
NVD-CWE-Other
|
CVE-2020-12647
|
2024-11-21 13:59 |
2020-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|