CVE-2020-12414
- EPSS 0.19%
- Veröffentlicht 09.07.2020 15:15:11
- Zuletzt bearbeitet 21.11.2024 04:59:40
IndexedDB should be cleared when leaving private browsing mode and it is not, the API for WKWebViewConfiguration was being used incorrectly and requires the private instance of this object be deleted when leaving private mode. This vulnerability affe...
CVE-2020-12415
- EPSS 0.35%
- Veröffentlicht 09.07.2020 15:15:11
- Zuletzt bearbeitet 21.11.2024 04:59:40
When "%2F" was present in a manifest URL, Firefox's AppCache behavior may have become confused and allowed a manifest to be served from a subdirectory. This could cause the appcache to be used to service requests for the top level directory. This vul...
CVE-2020-12416
- EPSS 0.67%
- Veröffentlicht 09.07.2020 15:15:11
- Zuletzt bearbeitet 21.11.2024 04:59:40
A VideoStreamEncoder may have been freed in a race condition with VideoBroadcaster::AddOrUpdateSink, resulting in a use-after-free, memory corruption, and a potentially exploitable crash. This vulnerability affects Firefox < 78.
CVE-2020-12417
- EPSS 0.48%
- Veröffentlicht 09.07.2020 15:15:11
- Zuletzt bearbeitet 21.11.2024 04:59:41
Due to confusion about ValueTags on JavaScript Objects, an object may pass through the type barrier, resulting in memory corruption and a potentially exploitable crash. *Note: this issue only affects Firefox on ARM64 platforms.* This vulnerability af...
CVE-2020-12418
- EPSS 1.24%
- Veröffentlicht 09.07.2020 15:15:11
- Zuletzt bearbeitet 21.11.2024 04:59:41
Manipulating individual parts of a URL object could have caused an out-of-bounds read, leaking process memory to malicious JavaScript. This vulnerability affects Firefox ESR < 68.10, Firefox < 78, and Thunderbird < 68.10.0.
CVE-2020-12419
- EPSS 0.46%
- Veröffentlicht 09.07.2020 15:15:11
- Zuletzt bearbeitet 21.11.2024 04:59:41
When processing callbacks that occurred during window flushing in the parent process, the associated window may die; causing a use-after-free condition. This could have led to memory corruption and a potentially exploitable crash. This vulnerability ...
CVE-2020-12420
- EPSS 0.44%
- Veröffentlicht 09.07.2020 15:15:11
- Zuletzt bearbeitet 21.11.2024 04:59:41
When trying to connect to a STUN server, a race condition could have caused a use-after-free of a pointer, leading to memory corruption and a potentially exploitable crash. This vulnerability affects Firefox ESR < 68.10, Firefox < 78, and Thunderbird...
CVE-2020-12399
- EPSS 0.1%
- Veröffentlicht 09.07.2020 15:15:10
- Zuletzt bearbeitet 21.11.2024 04:59:38
NSS has shown timing differences when performing DSA signatures, which was exploitable and could eventually leak private keys. This vulnerability affects Thunderbird < 68.9.0, Firefox < 77, and Firefox ESR < 68.9.
CVE-2020-12402
- EPSS 0.1%
- Veröffentlicht 09.07.2020 15:15:10
- Zuletzt bearbeitet 21.11.2024 04:59:38
During RSA key generation, bignum implementations used a variation of the Binary Extended Euclidean Algorithm which entailed significantly input-dependent flow. This allowed an attacker able to perform electromagnetic-based side channel attacks to re...
CVE-2020-12404
- EPSS 0.26%
- Veröffentlicht 09.07.2020 15:15:10
- Zuletzt bearbeitet 21.11.2024 04:59:39
For native-to-JS bridging the app requires a unique token to be passed that ensures non-app code can't call the bridging functions. That token could leak when used for downloading files. This vulnerability affects Firefox for iOS < 26.