Логотип exploitDog
bind:"CVE-2020-6800" OR bind:"CVE-2020-6798" OR bind:"CVE-2020-6796"
Консоль
Логотип exploitDog

exploitDog

bind:"CVE-2020-6800" OR bind:"CVE-2020-6798" OR bind:"CVE-2020-6796"

Количество 28

Количество 28

debian логотип

CVE-2020-6796

больше 5 лет назад

A content process could have modified shared memory relating to crash ...

CVSS3: 8.8
EPSS: Низкий
ubuntu логотип

CVE-2020-6798

больше 5 лет назад

If a template tag was used in a select tag, the parser could be confused and allow JavaScript parsing and execution when it should not be allowed. A site that relied on the browser behaving correctly could suffer a cross-site scripting vulnerability as a result. In general, this flaw cannot be exploited through email in the Thunderbird product because scripting is disabled when reading mail, but is potentially a risk in browser or browser-like contexts. This vulnerability affects Thunderbird < 68.5, Firefox < 73, and Firefox < ESR68.5.

CVSS3: 6.1
EPSS: Низкий
redhat логотип

CVE-2020-6798

больше 5 лет назад

If a template tag was used in a select tag, the parser could be confused and allow JavaScript parsing and execution when it should not be allowed. A site that relied on the browser behaving correctly could suffer a cross-site scripting vulnerability as a result. In general, this flaw cannot be exploited through email in the Thunderbird product because scripting is disabled when reading mail, but is potentially a risk in browser or browser-like contexts. This vulnerability affects Thunderbird < 68.5, Firefox < 73, and Firefox < ESR68.5.

CVSS3: 6.1
EPSS: Низкий
nvd логотип

CVE-2020-6798

больше 5 лет назад

If a template tag was used in a select tag, the parser could be confused and allow JavaScript parsing and execution when it should not be allowed. A site that relied on the browser behaving correctly could suffer a cross-site scripting vulnerability as a result. In general, this flaw cannot be exploited through email in the Thunderbird product because scripting is disabled when reading mail, but is potentially a risk in browser or browser-like contexts. This vulnerability affects Thunderbird < 68.5, Firefox < 73, and Firefox < ESR68.5.

CVSS3: 6.1
EPSS: Низкий
debian логотип

CVE-2020-6798

больше 5 лет назад

If a template tag was used in a select tag, the parser could be confus ...

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-mx5h-crf7-xxv9

больше 3 лет назад

A content process could have modified shared memory relating to crash reporting information, crash itself, and cause an out-of-bound write. This could have caused memory corruption and a potentially exploitable crash. This vulnerability affects Firefox < 73 and Firefox < ESR68.5.

EPSS: Низкий
fstec логотип

BDU:2023-07822

больше 5 лет назад

Уязвимость веб-браузеров Firefox и Firefox ESR, связанная с записью за границами буфера, позволяющая нарушителю получить доступ к конфиденциальным данным, нарушить их целостность, а также вызвать отказ в обслуживании

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-qwm2-p76q-cw3g

больше 3 лет назад

If a template tag was used in a select tag, the parser could be confused and allow JavaScript parsing and execution when it should not be allowed. A site that relied on the browser behaving correctly could suffer a cross-site scripting vulnerability as a result. In general, this flaw cannot be exploited through email in the Thunderbird product because scripting is disabled when reading mail, but is potentially a risk in browser or browser-like contexts. This vulnerability affects Thunderbird < 68.5, Firefox < 73, and Firefox < ESR68.5.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
debian логотип
CVE-2020-6796

A content process could have modified shared memory relating to crash ...

CVSS3: 8.8
1%
Низкий
больше 5 лет назад
ubuntu логотип
CVE-2020-6798

If a template tag was used in a select tag, the parser could be confused and allow JavaScript parsing and execution when it should not be allowed. A site that relied on the browser behaving correctly could suffer a cross-site scripting vulnerability as a result. In general, this flaw cannot be exploited through email in the Thunderbird product because scripting is disabled when reading mail, but is potentially a risk in browser or browser-like contexts. This vulnerability affects Thunderbird < 68.5, Firefox < 73, and Firefox < ESR68.5.

CVSS3: 6.1
1%
Низкий
больше 5 лет назад
redhat логотип
CVE-2020-6798

If a template tag was used in a select tag, the parser could be confused and allow JavaScript parsing and execution when it should not be allowed. A site that relied on the browser behaving correctly could suffer a cross-site scripting vulnerability as a result. In general, this flaw cannot be exploited through email in the Thunderbird product because scripting is disabled when reading mail, but is potentially a risk in browser or browser-like contexts. This vulnerability affects Thunderbird < 68.5, Firefox < 73, and Firefox < ESR68.5.

CVSS3: 6.1
1%
Низкий
больше 5 лет назад
nvd логотип
CVE-2020-6798

If a template tag was used in a select tag, the parser could be confused and allow JavaScript parsing and execution when it should not be allowed. A site that relied on the browser behaving correctly could suffer a cross-site scripting vulnerability as a result. In general, this flaw cannot be exploited through email in the Thunderbird product because scripting is disabled when reading mail, but is potentially a risk in browser or browser-like contexts. This vulnerability affects Thunderbird < 68.5, Firefox < 73, and Firefox < ESR68.5.

CVSS3: 6.1
1%
Низкий
больше 5 лет назад
debian логотип
CVE-2020-6798

If a template tag was used in a select tag, the parser could be confus ...

CVSS3: 6.1
1%
Низкий
больше 5 лет назад
github логотип
GHSA-mx5h-crf7-xxv9

A content process could have modified shared memory relating to crash reporting information, crash itself, and cause an out-of-bound write. This could have caused memory corruption and a potentially exploitable crash. This vulnerability affects Firefox < 73 and Firefox < ESR68.5.

1%
Низкий
больше 3 лет назад
fstec логотип
BDU:2023-07822

Уязвимость веб-браузеров Firefox и Firefox ESR, связанная с записью за границами буфера, позволяющая нарушителю получить доступ к конфиденциальным данным, нарушить их целостность, а также вызвать отказ в обслуживании

CVSS3: 8.8
1%
Низкий
больше 5 лет назад
github логотип
GHSA-qwm2-p76q-cw3g

If a template tag was used in a select tag, the parser could be confused and allow JavaScript parsing and execution when it should not be allowed. A site that relied on the browser behaving correctly could suffer a cross-site scripting vulnerability as a result. In general, this flaw cannot be exploited through email in the Thunderbird product because scripting is disabled when reading mail, but is potentially a risk in browser or browser-like contexts. This vulnerability affects Thunderbird < 68.5, Firefox < 73, and Firefox < ESR68.5.

1%
Низкий
больше 3 лет назад

Уязвимостей на страницу