Vulnerabilities > Mozilla
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2020-03-02 | CVE-2020-6795 | NULL Pointer Dereference vulnerability in Mozilla Thunderbird When processing a message that contains multiple S/MIME signatures, a bug in the MIME processing code caused a null pointer dereference, leading to an unexploitable crash. | 6.5 |
2020-03-02 | CVE-2020-6794 | Insufficiently Protected Credentials vulnerability in multiple products If a user saved passwords before Thunderbird 60 and then later set a master password, an unencrypted copy of these passwords is still accessible. | 6.5 |
2020-03-02 | CVE-2020-6793 | Use of Uninitialized Resource vulnerability in Mozilla Thunderbird When processing an email message with an ill-formed envelope, Thunderbird could read data from a random memory location. | 6.5 |
2020-03-02 | CVE-2020-6792 | Missing Initialization of Resource vulnerability in multiple products When deriving an identifier for an email message, uninitialized memory was used in addition to the message contents. | 4.3 |
2020-03-02 | CVE-2019-17026 | Type Confusion vulnerability in multiple products Incorrect alias information in IonMonkey JIT compiler for setting array elements could lead to a type confusion. | 8.8 |
2020-02-28 | CVE-2020-6804 | Cross-site Scripting vulnerability in Mozilla Webthings Gateway A reflected XSS vulnerability exists within the gateway, allowing an attacker to craft a specialized URL which could steal the user's authentication token. | 6.1 |
2020-02-28 | CVE-2020-6803 | Open Redirect vulnerability in Mozilla Webthings Gateway An open redirect is present on the gateway's login page, which could cause a user to be redirected to a malicious site after logging in. | 6.1 |
2020-02-18 | CVE-2013-4227 | Cross-Site Request Forgery (CSRF) vulnerability in Mozilla Persona Cross-site request forgery (CSRF) vulnerability in the persona_xsrf_token function in persona.module in the Mozilla Persona module 7.x-1.x before 7.x-1.11 for Drupal allows remote attackers to hijack the authentication of aribitrary users via a security token that is not a string data type. | 8.8 |
2020-02-18 | CVE-2013-5594 | Improper Restriction of Rendered UI Layers or Frames vulnerability in Mozilla Firefox Mozilla Firefox before 25 allows modification of anonymous content of pluginProblem.xml binding | 4.3 |
2020-01-21 | CVE-2011-2669 | Improper Certificate Validation vulnerability in Mozilla Firefox Mozilla Firefox prior to 3.6 has a DoS vulnerability due to an issue in the validation of certificates. | 6.5 |