|
210011
|
6.1 |
MEDIUM
Network
|
mapfish
|
print
|
In mapfish-print before version 3.24, a user can use the JSONP support to do a Cross-site scripting.
|
-
|
CVE-2020-15231
|
2024-11-21 14:05 |
2020-10-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210012
|
6.5 |
MEDIUM
Network
|
vapor_project
|
vapor
|
Vapor is a web framework for Swift. In Vapor before version 4.29.4, Attackers can access data at arbitrary filesystem paths on the same host as an application. Only applications using FileMiddleware …
|
-
|
CVE-2020-15230
|
2024-11-21 14:05 |
2020-10-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210013
|
8.8 |
HIGH
Network
|
mozilla opensuse debian
|
firefox_esr thunderbird firefox leap debian_linux
|
When recursing through graphical layers while scrolling, an iterator may have become invalid, resulting in a potential use-after-free. This occurs because the function APZCTreeManager::ComputeClipped…
|
CWE-416
Use After Free
|
CVE-2020-15678
|
2024-11-21 14:05 |
2020-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210014
|
6.1 |
MEDIUM
Network
|
mozilla debian opensuse
|
firefox_esr thunderbird firefox debian_linux leap
|
By exploiting an Open Redirect vulnerability on a website, an attacker could have spoofed the site displayed in the download file dialog to show the original site (the one suffering from the open red…
|
CWE-601
Open Redirect
|
CVE-2020-15677
|
2024-11-21 14:05 |
2020-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210015
|
6.1 |
MEDIUM
Network
|
mozilla debian opensuse
|
firefox_esr thunderbird firefox debian_linux leap
|
Firefox sometimes ran the onload handler for SVG elements that the DOM sanitizer decided to remove, resulting in JavaScript being executed after pasting attacker-controlled data into a contenteditabl…
|
CWE-79
Cross-site Scripting
|
CVE-2020-15676
|
2024-11-21 14:05 |
2020-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210016
|
8.8 |
HIGH
Network
|
mozilla
|
firefox
|
When processing surfaces, the lifetime may outlive a persistent buffer leading to memory corruption and a potentially exploitable crash. This vulnerability affects Firefox < 81.
|
CWE-416
Use After Free
|
CVE-2020-15675
|
2024-11-21 14:05 |
2020-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210017
|
8.8 |
HIGH
Network
|
mozilla
|
firefox
|
Mozilla developers reported memory safety bugs present in Firefox 80. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been expl…
|
CWE-787 CWE-667
Out-of-bounds Write Improper Locking
|
CVE-2020-15674
|
2024-11-21 14:05 |
2020-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210018
|
8.8 |
HIGH
Network
|
mozilla debian opensuse
|
firefox_esr thunderbird firefox debian_linux leap
|
Mozilla developers reported memory safety bugs present in Firefox 80 and Firefox ESR 78.2. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these…
|
CWE-416
Use After Free
|
CVE-2020-15673
|
2024-11-21 14:05 |
2020-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210019
|
3.1 |
LOW
Network
|
mozilla
|
firefox
|
When typing in a password under certain conditions, a race may have occured where the InputContext was not being correctly set for the input field, resulting in the typed password being saved to the …
|
CWE-200 CWE-362
Information Exposure Race Condition
|
CVE-2020-15671
|
2024-11-21 14:05 |
2020-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210020
|
8.8 |
HIGH
Network
|
mozilla
|
firefox firefox_esr thunderbird
|
Mozilla developers reported memory safety bugs present in Firefox for Android 79. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could ha…
|
CWE-362 CWE-416 CWE-617
Race Condition Use After Free Reachable Assertion
|
CVE-2020-15670
|
2024-11-21 14:05 |
2020-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|