Логотип exploitDog
bind:"CVE-2020-15664" OR bind:"CVE-2020-15669"
Консоль
Логотип exploitDog

exploitDog

bind:"CVE-2020-15664" OR bind:"CVE-2020-15669"

Количество 27

Количество 27

oracle-oval логотип

ELSA-2020-3643

почти 5 лет назад

ELSA-2020-3643: thunderbird security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2020-3634

почти 5 лет назад

ELSA-2020-3634: thunderbird security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2020-3631

почти 5 лет назад

ELSA-2020-3631: thunderbird security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2020-3558

почти 5 лет назад

ELSA-2020-3558: firefox security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2020-3556

почти 5 лет назад

ELSA-2020-3556: firefox security update (IMPORTANT)

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2020:1392-1

почти 5 лет назад

Security update for MozillaThunderbird

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2020:1383-1

почти 5 лет назад

Security update for MozillaThunderbird

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2020:2552-1

почти 5 лет назад

Security update for MozillaThunderbird

EPSS: Низкий
oracle-oval логотип

ELSA-2020-3557

почти 5 лет назад

ELSA-2020-3557: firefox security update (IMPORTANT)

EPSS: Низкий
ubuntu логотип

CVE-2020-15669

почти 5 лет назад

When aborting an operation, such as a fetch, an abort signal may be deleted while alerting the objects to be notified. This results in a use-after-free and we presume that with enough effort it could have been exploited to run arbitrary code. This vulnerability affects Firefox ESR < 68.12 and Thunderbird < 68.12.

CVSS3: 8.8
EPSS: Низкий
redhat логотип

CVE-2020-15669

около 5 лет назад

When aborting an operation, such as a fetch, an abort signal may be deleted while alerting the objects to be notified. This results in a use-after-free and we presume that with enough effort it could have been exploited to run arbitrary code. This vulnerability affects Firefox ESR < 68.12 and Thunderbird < 68.12.

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2020-15669

почти 5 лет назад

When aborting an operation, such as a fetch, an abort signal may be deleted while alerting the objects to be notified. This results in a use-after-free and we presume that with enough effort it could have been exploited to run arbitrary code. This vulnerability affects Firefox ESR < 68.12 and Thunderbird < 68.12.

CVSS3: 8.8
EPSS: Низкий
debian логотип

CVE-2020-15669

почти 5 лет назад

When aborting an operation, such as a fetch, an abort signal may be de ...

CVSS3: 8.8
EPSS: Низкий
ubuntu логотип

CVE-2020-15664

почти 5 лет назад

By holding a reference to the eval() function from an about:blank window, a malicious webpage could have gained access to the InstallTrigger object which would allow them to prompt the user to install an extension. Combined with user confusion, this could result in an unintended or malicious extension being installed. This vulnerability affects Firefox < 80, Thunderbird < 78.2, Thunderbird < 68.12, Firefox ESR < 68.12, Firefox ESR < 78.2, and Firefox for Android < 80.

CVSS3: 6.5
EPSS: Низкий
redhat логотип

CVE-2020-15664

около 5 лет назад

By holding a reference to the eval() function from an about:blank window, a malicious webpage could have gained access to the InstallTrigger object which would allow them to prompt the user to install an extension. Combined with user confusion, this could result in an unintended or malicious extension being installed. This vulnerability affects Firefox < 80, Thunderbird < 78.2, Thunderbird < 68.12, Firefox ESR < 68.12, Firefox ESR < 78.2, and Firefox for Android < 80.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2020-15664

почти 5 лет назад

By holding a reference to the eval() function from an about:blank window, a malicious webpage could have gained access to the InstallTrigger object which would allow them to prompt the user to install an extension. Combined with user confusion, this could result in an unintended or malicious extension being installed. This vulnerability affects Firefox < 80, Thunderbird < 78.2, Thunderbird < 68.12, Firefox ESR < 68.12, Firefox ESR < 78.2, and Firefox for Android < 80.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2020-15664

почти 5 лет назад

By holding a reference to the eval() function from an about:blank wind ...

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-8vqh-gxqj-vj4q

больше 3 лет назад

When aborting an operation, such as a fetch, an abort signal may be deleted while alerting the objects to be notified. This results in a use-after-free and we presume that with enough effort it could have been exploited to run arbitrary code. This vulnerability affects Firefox ESR < 68.12 and Thunderbird < 68.12.

EPSS: Низкий
fstec логотип

BDU:2022-05802

около 5 лет назад

Уязвимость браузера Mozilla Firefox ESR и почтового клиента Thunderbird, связанная с использованием памяти после ее освобождения, позволяющая нарушителю выполнить произвольный код

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-f4gc-pc7j-rfxr

больше 3 лет назад

By holding a reference to the eval() function from an about:blank window, a malicious webpage could have gained access to the InstallTrigger object which would allow them to prompt the user to install an extension. Combined with user confusion, this could result in an unintended or malicious extension being installed. This vulnerability affects Firefox < 80, Thunderbird < 78.2, Thunderbird < 68.12, Firefox ESR < 68.12, Firefox ESR < 78.2, and Firefox for Android < 80.

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
oracle-oval логотип
ELSA-2020-3643

ELSA-2020-3643: thunderbird security update (IMPORTANT)

почти 5 лет назад
oracle-oval логотип
ELSA-2020-3634

ELSA-2020-3634: thunderbird security update (IMPORTANT)

почти 5 лет назад
oracle-oval логотип
ELSA-2020-3631

ELSA-2020-3631: thunderbird security update (IMPORTANT)

почти 5 лет назад
oracle-oval логотип
ELSA-2020-3558

ELSA-2020-3558: firefox security update (IMPORTANT)

почти 5 лет назад
oracle-oval логотип
ELSA-2020-3556

ELSA-2020-3556: firefox security update (IMPORTANT)

почти 5 лет назад
suse-cvrf логотип
openSUSE-SU-2020:1392-1

Security update for MozillaThunderbird

почти 5 лет назад
suse-cvrf логотип
openSUSE-SU-2020:1383-1

Security update for MozillaThunderbird

почти 5 лет назад
suse-cvrf логотип
SUSE-SU-2020:2552-1

Security update for MozillaThunderbird

почти 5 лет назад
oracle-oval логотип
ELSA-2020-3557

ELSA-2020-3557: firefox security update (IMPORTANT)

почти 5 лет назад
ubuntu логотип
CVE-2020-15669

When aborting an operation, such as a fetch, an abort signal may be deleted while alerting the objects to be notified. This results in a use-after-free and we presume that with enough effort it could have been exploited to run arbitrary code. This vulnerability affects Firefox ESR < 68.12 and Thunderbird < 68.12.

CVSS3: 8.8
0%
Низкий
почти 5 лет назад
redhat логотип
CVE-2020-15669

When aborting an operation, such as a fetch, an abort signal may be deleted while alerting the objects to be notified. This results in a use-after-free and we presume that with enough effort it could have been exploited to run arbitrary code. This vulnerability affects Firefox ESR < 68.12 and Thunderbird < 68.12.

CVSS3: 8.8
0%
Низкий
около 5 лет назад
nvd логотип
CVE-2020-15669

When aborting an operation, such as a fetch, an abort signal may be deleted while alerting the objects to be notified. This results in a use-after-free and we presume that with enough effort it could have been exploited to run arbitrary code. This vulnerability affects Firefox ESR < 68.12 and Thunderbird < 68.12.

CVSS3: 8.8
0%
Низкий
почти 5 лет назад
debian логотип
CVE-2020-15669

When aborting an operation, such as a fetch, an abort signal may be de ...

CVSS3: 8.8
0%
Низкий
почти 5 лет назад
ubuntu логотип
CVE-2020-15664

By holding a reference to the eval() function from an about:blank window, a malicious webpage could have gained access to the InstallTrigger object which would allow them to prompt the user to install an extension. Combined with user confusion, this could result in an unintended or malicious extension being installed. This vulnerability affects Firefox < 80, Thunderbird < 78.2, Thunderbird < 68.12, Firefox ESR < 68.12, Firefox ESR < 78.2, and Firefox for Android < 80.

CVSS3: 6.5
0%
Низкий
почти 5 лет назад
redhat логотип
CVE-2020-15664

By holding a reference to the eval() function from an about:blank window, a malicious webpage could have gained access to the InstallTrigger object which would allow them to prompt the user to install an extension. Combined with user confusion, this could result in an unintended or malicious extension being installed. This vulnerability affects Firefox < 80, Thunderbird < 78.2, Thunderbird < 68.12, Firefox ESR < 68.12, Firefox ESR < 78.2, and Firefox for Android < 80.

CVSS3: 6.5
0%
Низкий
около 5 лет назад
nvd логотип
CVE-2020-15664

By holding a reference to the eval() function from an about:blank window, a malicious webpage could have gained access to the InstallTrigger object which would allow them to prompt the user to install an extension. Combined with user confusion, this could result in an unintended or malicious extension being installed. This vulnerability affects Firefox < 80, Thunderbird < 78.2, Thunderbird < 68.12, Firefox ESR < 68.12, Firefox ESR < 78.2, and Firefox for Android < 80.

CVSS3: 6.5
0%
Низкий
почти 5 лет назад
debian логотип
CVE-2020-15664

By holding a reference to the eval() function from an about:blank wind ...

CVSS3: 6.5
0%
Низкий
почти 5 лет назад
github логотип
GHSA-8vqh-gxqj-vj4q

When aborting an operation, such as a fetch, an abort signal may be deleted while alerting the objects to be notified. This results in a use-after-free and we presume that with enough effort it could have been exploited to run arbitrary code. This vulnerability affects Firefox ESR < 68.12 and Thunderbird < 68.12.

0%
Низкий
больше 3 лет назад
fstec логотип
BDU:2022-05802

Уязвимость браузера Mozilla Firefox ESR и почтового клиента Thunderbird, связанная с использованием памяти после ее освобождения, позволяющая нарушителю выполнить произвольный код

CVSS3: 8.8
0%
Низкий
около 5 лет назад
github логотип
GHSA-f4gc-pc7j-rfxr

By holding a reference to the eval() function from an about:blank window, a malicious webpage could have gained access to the InstallTrigger object which would allow them to prompt the user to install an extension. Combined with user confusion, this could result in an unintended or malicious extension being installed. This vulnerability affects Firefox < 80, Thunderbird < 78.2, Thunderbird < 68.12, Firefox ESR < 68.12, Firefox ESR < 78.2, and Firefox for Android < 80.

CVSS3: 6.5
0%
Низкий
больше 3 лет назад

Уязвимостей на страницу