Vulnerabilities > Mozilla > Medium

DATE CVE VULNERABILITY TITLE RISK
2020-07-09 CVE-2020-12399 Information Exposure Through Discrepancy vulnerability in multiple products
NSS has shown timing differences when performing DSA signatures, which was exploitable and could eventually leak private keys.
local
high complexity
mozilla debian CWE-203
4.4
2020-07-09 CVE-2020-12424 Incorrect Default Permissions vulnerability in multiple products
When constructing a permission prompt for WebRTC, a URI was supplied from the content process.
network
low complexity
mozilla opensuse CWE-276
6.5
2020-05-26 CVE-2020-12392 Path Traversal vulnerability in multiple products
The 'Copy as cURL' feature of Devtools' network tab did not properly escape the HTTP POST data of a request, which can be controlled by the website.
local
low complexity
mozilla canonical CWE-22
5.5
2020-05-22 CVE-2020-12397 Origin Validation Error vulnerability in multiple products
By encoding Unicode whitespace characters within the From email header, an attacker can spoof the sender email address that Thunderbird displays.
network
low complexity
mozilla canonical CWE-346
4.3
2020-04-24 CVE-2020-6827 Improper Restriction of Rendered UI Layers or Frames vulnerability in Mozilla Firefox ESR
When following a link that opened an intent://-schemed URL, causing a custom tab to be opened, Firefox for Android could be tricked into displaying the incorrect URI.
network
low complexity
mozilla CWE-1021
4.7
2020-03-25 CVE-2020-6813 Unspecified vulnerability in Mozilla Firefox
When protecting CSS blocks with the nonce feature of Content Security Policy, the @import statement in the CSS block could allow an attacker to inject arbitrary styles, bypassing the intent of the Content Security Policy.
network
low complexity
mozilla
5.3
2020-03-25 CVE-2020-6812 Information Exposure vulnerability in multiple products
The first time AirPods are connected to an iPhone, they become named after the user's name by default (e.g.
network
low complexity
mozilla canonical CWE-200
5.3
2020-03-25 CVE-2020-6810 Authentication Bypass by Spoofing vulnerability in Mozilla Firefox
After a website had entered fullscreen mode, it could have used a previously opened popup to obscure the notification that indicates the browser is in fullscreen mode.
network
low complexity
mozilla CWE-290
4.3
2020-03-25 CVE-2020-6808 Authentication Bypass by Spoofing vulnerability in Mozilla Firefox
When a JavaScript URL (javascript:) is evaluated and the result is a string, this string is parsed to create an HTML document, which is then presented.
network
low complexity
mozilla CWE-290
6.5
2020-03-24 CVE-2020-6816 Cross-site Scripting vulnerability in multiple products
In Mozilla Bleach before 3.12, a mutation XSS in bleach.clean when RCDATA and either svg or math tags are whitelisted and the keyword argument strip=False.
network
low complexity
mozilla fedoraproject CWE-79
6.1