[Forgot Password]
Login  Register Subscribe

30480

 
 

423868

 
 

251782

 
 

909

 
 

196543

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

ALAS2-2020-1572 --- thunderbird

ID: oval:org.secpod.oval:def:1700528Date: (C)2020-12-14   (M)2024-02-19
Class: PATCHFamily: unix




The Mozilla Foundation Security Advisory describes this flaw as:Mozilla developer reported memory safety bugs present in Firefox 80 and Firefox ESR 78.2. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. The Mozilla Foundation Security Advisory describes this flaw as:Firefox sometimes ran the onload handler for SVG elements that the DOM sanitizer decided to remove, resulting in JavaScript being executed after pasting attacker-controlled data into a contenteditable element. The Mozilla Foundation Security Advisory describes this flaw as:By exploiting an Open Redirect vulnerability on a website, an attacker could have spoofed the site displayed in the download file dialog to show the original site rather than the site the file was actually downloaded from. The Mozilla Foundation Security Advisory describes this flaw as:When recursing through graphical layers while scrolling, an iterator may have become invalid, resulting in a potential use-after-free. This occurs because the function `APZCTreeManager::ComputeClippedCompositionBounds` did not follow iterator invalidation rules. Mozilla developers and community members reported memory safety bugs present in Firefox 81 and Firefox ESR 78.3. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox ESR CVE-2020-15683 (CVE-2020-15969 (CVE-2020-26950

Platform:
Amazon Linux 2
Product:
thunderbird
Reference:
ALAS2-2020-1572
CVE-2020-15673
CVE-2020-15676
CVE-2020-15677
CVE-2020-15678
CVE-2020-15683
CVE-2020-15969
CVE-2020-26950
CVE    7
CVE-2020-15678
CVE-2020-15677
CVE-2020-15673
CVE-2020-15676
...

© SecPod Technologies