|
209661
|
8.8 |
HIGH
Network
|
mozilla
|
thunderbird
|
When reading SMTP server status codes, Thunderbird writes an integer value to a position on the stack that is intended to contain just one byte. Depending on processor architecture and stack layout, …
|
CWE-787
Out-of-bounds Write
|
CVE-2020-26970
|
2024-11-21 14:20 |
2020-12-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209662
|
8.8 |
HIGH
Network
|
mozilla
|
firefox
|
Mozilla developers reported memory safety bugs present in Firefox 82. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been expl…
|
CWE-787
Out-of-bounds Write
|
CVE-2020-26969
|
2024-11-21 14:20 |
2020-12-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209663
|
8.8 |
HIGH
Network
|
mozilla
|
firefox firefox_esr thunderbird
|
Mozilla developers reported memory safety bugs present in Firefox 82 and Firefox ESR 78.4. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these…
|
CWE-787
Out-of-bounds Write
|
CVE-2020-26968
|
2024-11-21 14:20 |
2020-12-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209664
|
6.5 |
MEDIUM
Network
|
mozilla
|
firefox
|
When listening for page changes with a Mutation Observer, a malicious web page could confuse Firefox Screenshots into interacting with elements other than those that it injected into the page. This w…
|
NVD-CWE-noinfo
|
CVE-2020-26967
|
2024-11-21 14:20 |
2020-12-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209665
|
6.5 |
MEDIUM
Network
|
mozilla
|
firefox firefox_esr thunderbird
|
Searching for a single word from the address bar caused an mDNS request to be sent on the local network searching for a hostname consisting of that string; resulting in an information leak. *Note: Th…
|
NVD-CWE-Other
|
CVE-2020-26966
|
2024-11-21 14:20 |
2020-12-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209666
|
4.3 |
MEDIUM
Network
|
mozilla
|
firefox
|
Repeated calls to the history and location interfaces could have been used to hang the browser. This was addressed by introducing rate-limiting to these API calls. This vulnerability affects Firefox …
|
NVD-CWE-noinfo
|
CVE-2020-26963
|
2024-11-21 14:20 |
2020-12-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209667
|
6.5 |
MEDIUM
Network
|
mozilla
|
firefox firefox_esr thunderbird
|
Some websites have a feature "Show Password" where clicking a button will change a password field into a textbook field, revealing the typed password. If, when using a software keyboard that remember…
|
CWE-212
Improper Removal of Sensitive Information Before Storage or Transfer
|
CVE-2020-26965
|
2024-11-21 14:20 |
2020-12-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209668
|
6.8 |
MEDIUM
Network
|
mozilla
|
firefox
|
If the Remote Debugging via USB feature was enabled in Firefox for Android on an Android version prior to Android 6.0, untrusted apps could have connected to the feature and operated with the privile…
|
NVD-CWE-noinfo
|
CVE-2020-26964
|
2024-11-21 14:20 |
2020-12-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209669
|
6.1 |
MEDIUM
Network
|
mozilla
|
firefox
|
Cross-origin iframes that contained a login form could have been recognized by the login autofill service, and populated. This could have been used in clickjacking attacks, as well as be read across …
|
CWE-1021
Improper Restriction of Rendered UI Layers or Frames
|
CVE-2020-26962
|
2024-11-21 14:20 |
2020-12-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209670
|
6.5 |
MEDIUM
Network
|
mozilla
|
firefox firefox_esr thunderbird
|
When DNS over HTTPS is in use, it intentionally filters RFC1918 and related IP ranges from the responses as these do not make sense coming from a DoH resolver. However when an IPv4 address was mapped…
|
NVD-CWE-noinfo
|
CVE-2020-26961
|
2024-11-21 14:20 |
2020-12-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|