CVE-2020-12415
- EPSS 0.35%
- Veröffentlicht 09.07.2020 15:15:11
- Zuletzt bearbeitet 21.11.2024 04:59:40
When "%2F" was present in a manifest URL, Firefox's AppCache behavior may have become confused and allowed a manifest to be served from a subdirectory. This could cause the appcache to be used to service requests for the top level directory. This vul...
CVE-2020-12416
- EPSS 0.67%
- Veröffentlicht 09.07.2020 15:15:11
- Zuletzt bearbeitet 21.11.2024 04:59:40
A VideoStreamEncoder may have been freed in a race condition with VideoBroadcaster::AddOrUpdateSink, resulting in a use-after-free, memory corruption, and a potentially exploitable crash. This vulnerability affects Firefox < 78.
CVE-2020-12417
- EPSS 0.38%
- Veröffentlicht 09.07.2020 15:15:11
- Zuletzt bearbeitet 21.11.2024 04:59:41
Due to confusion about ValueTags on JavaScript Objects, an object may pass through the type barrier, resulting in memory corruption and a potentially exploitable crash. *Note: this issue only affects Firefox on ARM64 platforms.* This vulnerability af...
CVE-2020-12418
- EPSS 1.58%
- Veröffentlicht 09.07.2020 15:15:11
- Zuletzt bearbeitet 21.11.2024 04:59:41
Manipulating individual parts of a URL object could have caused an out-of-bounds read, leaking process memory to malicious JavaScript. This vulnerability affects Firefox ESR < 68.10, Firefox < 78, and Thunderbird < 68.10.0.
CVE-2020-12419
- EPSS 0.44%
- Veröffentlicht 09.07.2020 15:15:11
- Zuletzt bearbeitet 21.11.2024 04:59:41
When processing callbacks that occurred during window flushing in the parent process, the associated window may die; causing a use-after-free condition. This could have led to memory corruption and a potentially exploitable crash. This vulnerability ...
CVE-2020-12420
- EPSS 0.42%
- Veröffentlicht 09.07.2020 15:15:11
- Zuletzt bearbeitet 21.11.2024 04:59:41
When trying to connect to a STUN server, a race condition could have caused a use-after-free of a pointer, leading to memory corruption and a potentially exploitable crash. This vulnerability affects Firefox ESR < 68.10, Firefox < 78, and Thunderbird...
CVE-2020-12399
- EPSS 0.1%
- Veröffentlicht 09.07.2020 15:15:10
- Zuletzt bearbeitet 21.11.2024 04:59:38
NSS has shown timing differences when performing DSA signatures, which was exploitable and could eventually leak private keys. This vulnerability affects Thunderbird < 68.9.0, Firefox < 77, and Firefox ESR < 68.9.
CVE-2020-12402
- EPSS 0.1%
- Veröffentlicht 09.07.2020 15:15:10
- Zuletzt bearbeitet 21.11.2024 04:59:38
During RSA key generation, bignum implementations used a variation of the Binary Extended Euclidean Algorithm which entailed significantly input-dependent flow. This allowed an attacker able to perform electromagnetic-based side channel attacks to re...
CVE-2020-12404
- EPSS 0.26%
- Veröffentlicht 09.07.2020 15:15:10
- Zuletzt bearbeitet 21.11.2024 04:59:39
For native-to-JS bridging the app requires a unique token to be passed that ensures non-app code can't call the bridging functions. That token could leak when used for downloading files. This vulnerability affects Firefox for iOS < 26.
CVE-2020-12405
- EPSS 0.66%
- Veröffentlicht 09.07.2020 15:15:10
- Zuletzt bearbeitet 21.11.2024 04:59:39
When browsing a malicious page, a race condition in our SharedWorkerService could occur and lead to a potentially exploitable crash. This vulnerability affects Thunderbird < 68.9.0, Firefox < 77, and Firefox ESR < 68.9.