Vulnerabilities > Mozilla
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2020-08-10 | CVE-2020-15651 | Unspecified vulnerability in Mozilla Firefox A unicode RTL order character in the downloaded file name can be used to change the file's name during the download UI flow to change the file extension. | 4.3 |
2020-08-10 | CVE-2020-15650 | Unspecified vulnerability in Mozilla Firefox ESR Given an installed malicious file picker application, an attacker was able to overwrite local files and thus overwrite Firefox settings (but not access the previous profile). | 5.5 |
2020-08-10 | CVE-2020-15649 | Unrestricted Upload of File with Dangerous Type vulnerability in Mozilla Firefox ESR Given an installed malicious file picker application, an attacker was able to steal and upload local files of their choosing, regardless of the actually files picked. | 5.5 |
2020-08-10 | CVE-2020-15648 | Improper Restriction of Rendered UI Layers or Frames vulnerability in Mozilla Firefox Using object or embed tags, it was possible to frame other websites, even if they disallowed framing using the X-Frame-Options header. | 6.5 |
2020-08-10 | CVE-2020-15647 | Information Exposure vulnerability in Mozilla Firefox A Content Provider in Firefox for Android allowed local files accessible by the browser to be read by a remote webpage, leading to sensitive data disclosure, including cookies for other origins. | 7.4 |
2020-07-09 | CVE-2020-12426 | Out-of-bounds Write vulnerability in multiple products Mozilla developers and community members reported memory safety bugs present in Firefox 77. | 8.8 |
2020-07-09 | CVE-2020-12425 | Out-of-bounds Read vulnerability in Mozilla Firefox Due to confusion processing a hyphen character in Date.parse(), a one-byte out of bounds read could have occurred, leading to potential information disclosure. | 6.5 |
2020-07-09 | CVE-2020-12423 | Uncontrolled Search Path Element vulnerability in Mozilla Firefox When the Windows DLL "webauthn.dll" was missing from the Operating System, and a malicious one was placed in a folder in the user's %PATH%, Firefox may have loaded the DLL, leading to arbitrary code execution. | 7.8 |
2020-07-09 | CVE-2020-12422 | Out-of-bounds Write vulnerability in multiple products In non-standard configurations, a JPEG image created by JavaScript could have caused an internal variable to overflow, resulting in an out of bounds write, memory corruption, and a potentially exploitable crash. | 8.8 |
2020-07-09 | CVE-2020-12421 | Improper Certificate Validation vulnerability in multiple products When performing add-on updates, certificate chains terminating in non-built-in-roots were rejected (even if they were legitimately added by an administrator.) This could have caused add-ons to become out-of-date silently without notification to the user. | 6.5 |