Vulnerabilities > Mozilla > Firefox > 3.0.12
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2020-05-26 | CVE-2020-12394 | Unspecified vulnerability in Mozilla Firefox A logic flaw in our location bar implementation could have allowed a local attacker to spoof the current location by selecting a different origin and removing focus from the input element. | 2.1 |
2020-05-26 | CVE-2020-12393 | Injection vulnerability in Mozilla Firefox The 'Copy as cURL' feature of Devtools' network tab did not properly escape the HTTP method of a request, which can be controlled by the website. | 4.6 |
2020-04-24 | CVE-2020-6826 | Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Mozilla Firefox Mozilla developers Tyson Smith, Bob Clary, and Alexandru Michis reported memory safety bugs present in Firefox 74. | 7.5 |
2020-04-24 | CVE-2020-6825 | Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Mozilla Firefox Mozilla developers and community members Tyson Smith and Christian Holler reported memory safety bugs present in Firefox 74 and Firefox ESR 68.6. | 7.5 |
2020-04-24 | CVE-2020-6824 | Session Fixation vulnerability in Mozilla Firefox Initially, a user opens a Private Browsing Window and generates a password for a site, then closes the Private Browsing Window but leaves Firefox open. | 1.9 |
2020-04-24 | CVE-2020-6823 | Improper Privilege Management vulnerability in Mozilla Firefox A malicious extension could have called <code>browser.identity.launchWebAuthFlow</code>, controlling the redirect_uri, and through the Promise returned, obtain the Auth code and gain access to the user's account at the service provider. | 7.5 |
2020-04-24 | CVE-2020-6822 | Out-of-bounds Write vulnerability in Mozilla Firefox On 32-bit builds, an out of bounds write could have occurred when processing an image larger than 4 GB in <code>GMPDecodeData</code>. | 6.8 |
2020-04-24 | CVE-2020-6821 | Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Mozilla Firefox When reading from areas partially or fully outside the source resource with WebGL's <code>copyTexSubImage</code> method, the specification requires the returned values be zero. | 5.0 |
2020-04-24 | CVE-2020-6820 | Race Condition vulnerability in Mozilla Thunderbird Under certain conditions, when handling a ReadableStream, a race condition can cause a use-after-free. | 6.8 |
2020-04-24 | CVE-2020-6819 | Use After Free vulnerability in Mozilla Thunderbird Under certain conditions, when running the nsDocShell destructor, a race condition can cause a use-after-free. | 8.1 |