CVE-2020-12399
- EPSS 0.1%
- Published 09.07.2020 15:15:10
- Last modified 21.11.2024 04:59:38
NSS has shown timing differences when performing DSA signatures, which was exploitable and could eventually leak private keys. This vulnerability affects Thunderbird < 68.9.0, Firefox < 77, and Firefox ESR < 68.9.
CVE-2020-12402
- EPSS 0.08%
- Published 09.07.2020 15:15:10
- Last modified 21.11.2024 04:59:38
During RSA key generation, bignum implementations used a variation of the Binary Extended Euclidean Algorithm which entailed significantly input-dependent flow. This allowed an attacker able to perform electromagnetic-based side channel attacks to re...
CVE-2020-12404
- EPSS 0.26%
- Published 09.07.2020 15:15:10
- Last modified 21.11.2024 04:59:39
For native-to-JS bridging the app requires a unique token to be passed that ensures non-app code can't call the bridging functions. That token could leak when used for downloading files. This vulnerability affects Firefox for iOS < 26.
CVE-2020-12405
- EPSS 0.72%
- Published 09.07.2020 15:15:10
- Last modified 21.11.2024 04:59:39
When browsing a malicious page, a race condition in our SharedWorkerService could occur and lead to a potentially exploitable crash. This vulnerability affects Thunderbird < 68.9.0, Firefox < 77, and Firefox ESR < 68.9.
CVE-2018-12371
- EPSS 0.44%
- Published 09.07.2020 14:15:10
- Last modified 21.11.2024 03:45:04
An integer overflow vulnerability in the Skia library when allocating memory for edge builders on some systems with at least 16 GB of RAM. This results in the use of uninitialized memory, resulting in a potentially exploitable crash. This vulnerabili...
CVE-2020-12424
- EPSS 0.16%
- Published 09.07.2020 14:15:10
- Last modified 21.11.2024 04:59:42
When constructing a permission prompt for WebRTC, a URI was supplied from the content process. This URI was untrusted, and could have been the URI of an origin that was previously granted permission; bypassing the prompt. This vulnerability affects F...
- EPSS 1.5%
- Published 26.05.2020 18:15:11
- Last modified 21.11.2024 04:59:37
The Firefox content processes did not sufficiently lockdown access control which could result in a sandbox escape. *Note: this issue only affects Firefox on Windows operating systems.*. This vulnerability affects Firefox ESR < 68.8 and Firefox < 76.
- EPSS 0.56%
- Published 26.05.2020 18:15:11
- Last modified 21.11.2024 04:59:37
The Firefox content processes did not sufficiently lockdown access control which could result in a sandbox escape. *Note: this issue only affects Firefox on Windows operating systems.*. This vulnerability affects Firefox ESR < 68.8 and Firefox < 76.
CVE-2020-12390
- EPSS 1.7%
- Published 26.05.2020 18:15:11
- Last modified 21.11.2024 04:59:37
Incorrect origin serialization of URLs with IPv6 addresses could lead to incorrect security checks. This vulnerability affects Firefox < 76.
CVE-2020-12391
- EPSS 0.7%
- Published 26.05.2020 18:15:11
- Last modified 21.11.2024 04:59:37
Documents formed using data: URLs in an OBJECT element failed to inherit the CSP of the creating context. This allowed the execution of scripts that should have been blocked, albeit with a unique opaque origin. This vulnerability affects Firefox < 76...