Vulnerabilities > Mozilla > Firefox > 73.0.1
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2020-07-09 | CVE-2020-12417 | Incorrect Conversion between Numeric Types vulnerability in multiple products Due to confusion about ValueTags on JavaScript Objects, an object may pass through the type barrier, resulting in memory corruption and a potentially exploitable crash. | 9.3 |
2020-07-09 | CVE-2020-12416 | Use After Free vulnerability in multiple products A VideoStreamEncoder may have been freed in a race condition with VideoBroadcaster::AddOrUpdateSink, resulting in a use-after-free, memory corruption, and a potentially exploitable crash. | 9.3 |
2020-07-09 | CVE-2020-12415 | Incorrect Default Permissions vulnerability in multiple products When "%2F" was present in a manifest URL, Firefox's AppCache behavior may have become confused and allowed a manifest to be served from a subdirectory. | 6.5 |
2020-07-09 | CVE-2020-12411 | Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Mozilla Firefox Mozilla developers reported memory safety bugs present in Firefox 76. | 9.3 |
2020-07-09 | CVE-2020-12410 | Out-of-bounds Write vulnerability in multiple products Mozilla developers reported memory safety bugs present in Firefox 76 and Firefox ESR 68.8. | 9.3 |
2020-07-09 | CVE-2020-12409 | Unspecified vulnerability in Mozilla Firefox When using certain blank characters in a URL, they where incorrectly rendered as spaces instead of an encoded URL. network mozilla | 6.8 |
2020-07-09 | CVE-2020-12408 | Injection vulnerability in Mozilla Firefox When browsing a document hosted on an IP address, an attacker could insert certain characters to flip domain and path information in the address bar. | 4.3 |
2020-07-09 | CVE-2020-12407 | Information Exposure vulnerability in Mozilla Firefox Mozilla Developer Nicolas Silva found that when using WebRender, Firefox would under certain conditions leak arbitrary GPU memory to the visible screen. | 2.6 |
2020-07-09 | CVE-2020-12406 | Insufficient Verification of Data Authenticity vulnerability in multiple products Mozilla Developer Iain Ireland discovered a missing type check during unboxed objects removal, resulting in a crash. | 8.8 |
2020-07-09 | CVE-2020-12405 | Use After Free vulnerability in multiple products When browsing a malicious page, a race condition in our SharedWorkerService could occur and lead to a potentially exploitable crash. | 2.6 |