Top technology
Linux 13140
Google 12530
Microsoft 12379
Oracle 6737
Apple 6692
Adobe 6387
Ibm 6330
Cisco 5757
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 6.5
CVE-2020-12414
IndexedDB should be cleared when leaving private browsing mode and it is not, the API for WKWebViewConfiguration was being used incorrectly and requi…
Firefox Mobile
27.0+
MEDIUM 6.5
CVE-2020-12415
When "%2F" was present in a manifest URL, Firefox's AppCache behavior may have become confused and allowed a manifest to be served from a subdirector…
Firefox
78.0+
MEDIUM 6.5
CVE-2020-12418
Manipulating individual parts of a URL object could have caused an out-of-bounds read, leaking process memory to malicious JavaScript. This vulnerabi…
Firefox
68.10 / 68.10.0+
MEDIUM 5.3
CVE-2020-12405
When browsing a malicious page, a race condition in our SharedWorkerService could occur and lead to a potentially exploitable crash. This vulnerabili…
Firefox
68.9.0 / 77.0+
HIGH 8.8
CVE-2018-12371
An integer overflow vulnerability in the Skia library when allocating memory for edge builders on some systems with at least 16 GB of RAM. This resul…
Firefox
60.0 / 60.1.0+
MEDIUM 6.5
CVE-2020-12424
When constructing a permission prompt for WebRTC, a URI was supplied from the content process. This URI was untrusted, and could have been the URI of…
Firefox
78.0+
CRITICAL 10.0
CVE-2020-12388
The Firefox content processes did not sufficiently lockdown access control which could result in a sandbox escape. *Note: this issue only affects Fir…
Firefox
68.8.0 / 76.0+
CRITICAL 10.0
CVE-2020-12389
The Firefox content processes did not sufficiently lockdown access control which could result in a sandbox escape. *Note: this issue only affects Fir…
Firefox
68.8.0 / 76.0+
CRITICAL 9.8
CVE-2020-12390
Incorrect origin serialization of URLs with IPv6 addresses could lead to incorrect security checks. This vulnerability affects Firefox < 76.
Firefox
76.0+
CRITICAL 9.8
CVE-2020-6831EPSS 6%
A buffer overflow could occur when parsing and validating SCTP chunks in WebRTC. This could have led to memory corruption and a potentially exploitab…
Firefox
68.8.0 / 76.0+
HIGH 7.5
CVE-2020-12391
Documents formed using data: URLs in an OBJECT element failed to inherit the CSP of the creating context. This allowed the execution of scripts that …
Firefox
76.0+
HIGH 7.5
CVE-2020-6830
For native-to-JS bridging, the app requires a unique token to be passed that ensures non-app code can't call the bridging functions. That token was b…
Firefox Mobile
25.0+
MEDIUM 5.5
CVE-2020-12392
The 'Copy as cURL' feature of Devtools' network tab did not properly escape the HTTP POST data of a request, which can be controlled by the website. …
Firefox
68.8.0 / 76.0+
HIGH 8.1
CVE-2020-12387
A race condition when running shutdown code for Web Worker led to a use-after-free vulnerability. This resulted in a potentially exploitable crash. T…
Firefox
68.8.0 / 76.0+
CRITICAL 9.8
CVE-2020-12395
Mozilla developers and community members reported memory safety bugs present in Firefox 75 and Firefox ESR 68.7. Some of these bugs showed evidence o…
Firefox
68.8.0 / 76.0+
CRITICAL 9.8
CVE-2020-12396
Mozilla developers and community members reported memory safety bugs present in Firefox 75. Some of these bugs showed evidence of memory corruption a…
Firefox
76.0+
HIGH 7.8
CVE-2020-12393
The 'Copy as cURL' feature of Devtools' network tab did not properly escape the HTTP method of a request, which can be controlled by the website. If …
Firefox
68.8.0 / 76.0+
CRITICAL 9.8
CVE-2020-6823
A malicious extension could have called <code>browser.identity.launchWebAuthFlow</code>, controlling the redirect_uri, and through the Promise return…
Firefox
75.0+
CRITICAL 9.8
CVE-2020-6825
Mozilla developers and community members Tyson Smith and Christian Holler reported memory safety bugs present in Firefox 74 and Firefox ESR 68.6. Som…
Firefox
68.7.0 / 75.0+
CRITICAL 9.8
CVE-2020-6826
Mozilla developers Tyson Smith, Bob Clary, and Alexandru Michis reported memory safety bugs present in Firefox 74. Some of these bugs showed evidence…
Firefox
75.0+
HIGH 8.8
CVE-2020-6822
On 32-bit builds, an out of bounds write could have occurred when processing an image larger than 4 GB in <code>GMPDecodeData</code>. It is possible …
Firefox
68.7.0 / 75.0+
HIGH 8.1
CVE-2020-6819 KEV
Under certain conditions, when running the nsDocShell destructor, a race condition can cause a use-after-free. We are aware of targeted attacks in th…
Firefox
68.6.1 / 68.7.0+
HIGH 8.1
CVE-2020-6820 KEVEPSS 6%
Under certain conditions, when handling a ReadableStream, a race condition can cause a use-after-free. We are aware of targeted attacks in the wild a…
Firefox
68.6.1 / 68.7.0+
HIGH 7.5
CVE-2020-6821
When reading from areas partially or fully outside the source resource with WebGL's <code>copyTexSubImage</code> method, the specification requires t…
Firefox
68.7.0 / 75.0+
HIGH 7.5
CVE-2020-6828
A malicious Android application could craft an Intent that would have been processed by Firefox for Android and potentially result in a file overwrit…
Firefox Esr
68.7.0+
CRITICAL 9.8
CVE-2020-6814
Mozilla developers reported memory safety bugs present in Firefox and Thunderbird 68.5. Some of these bugs showed evidence of memory corruption and w…
Firefox
68.6.0 / 74.0+
CRITICAL 9.8
CVE-2020-6815
Mozilla developers reported memory safety and script safety bugs present in Firefox 73. Some of these bugs showed evidence of memory corruption or es…
Firefox
74.0+
HIGH 8.8
CVE-2020-6805
When removing data about an origin whose tab was recently closed, a use-after-free could occur in the Quota manager, resulting in a potentially explo…
Firefox
68.6.0 / 74.0+
HIGH 8.8
CVE-2020-6806
By carefully crafting promise resolutions, it was possible to cause an out-of-bounds read off the end of an array resized during script execution. Th…
Firefox
68.6.0 / 74.0+
HIGH 8.8
CVE-2020-6807
When a device was changed while a stream was about to be destroyed, the <code>stream-reinit</code> task may have been executed after the stream was d…
Firefox
68.6.0 / 74.0+