
CVE-2020-12420 – Mozilla: Use-After-Free when trying to connect to a STUN server
https://notcve.org/view.php?id=CVE-2020-12420
02 Jul 2020 — When trying to connect to a STUN server, a race condition could have caused a use-after-free of a pointer, leading to memory corruption and a potentially exploitable crash. This vulnerability affects Firefox ESR < 68.10, Firefox < 78, and Thunderbird < 68.10.0. Al intentar conectarse a un servidor STUN, una condición de carrera podría haber causado un uso de la memoria previamente liberada de un puntero, conllevando a una corrupción de la memoria y un bloqueo potencialmente explotable. Esta vulnerabilidad a... • http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00023.html • CWE-362: Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') CWE-416: Use After Free •

CVE-2020-12424 – Mozilla: WebRTC permission prompt could have been bypassed by a compromised content process
https://notcve.org/view.php?id=CVE-2020-12424
02 Jul 2020 — When constructing a permission prompt for WebRTC, a URI was supplied from the content process. This URI was untrusted, and could have been the URI of an origin that was previously granted permission; bypassing the prompt. This vulnerability affects Firefox < 78. Cuando se construye un aviso de permiso para WebRTC, se suministraba un URI desde el proceso de contenido. Este URI no era confiable, y podría haber sido el URI de un origen que previamente se le concediera permiso; omitiendo el aviso. • http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00027.html • CWE-276: Incorrect Default Permissions CWE-451: User Interface (UI) Misrepresentation of Critical Information •

CVE-2020-12409 – Gentoo Linux Security Advisory 202006-07
https://notcve.org/view.php?id=CVE-2020-12409
12 Jun 2020 — When using certain blank characters in a URL, they where incorrectly rendered as spaces instead of an encoded URL. This vulnerability affects Firefox < 77. Cuando usan determinados caracteres en blanco en una URL, fueron incorrectamente renderizados como espacios en lugar de una URL codificada. Esta vulnerabilidad afecta a Firefox versiones anteriores a 77 Multiple vulnerabilities have been found in Mozilla Firefox, the worst of which could result in the arbitrary execution of code. Versions less than 68.9.... • https://bugzilla.mozilla.org/show_bug.cgi?id=1629506 •

CVE-2020-12411 – Gentoo Linux Security Advisory 202006-07
https://notcve.org/view.php?id=CVE-2020-12411
05 Jun 2020 — Mozilla developers reported memory safety bugs present in Firefox 76. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 77. Los desarrolladores de Mozilla reportaron bugs de seguridad de la memoria presentes en Firefox versión 76. Algunos de estos bugs mostraron evidencia de corrupción de la memoria y presumimos que con suficiente esfuerzo algunos de estos podrían ... • https://bugzilla.mozilla.org/buglist.cgi?bug_id=1620972%2C1625333 • CWE-787: Out-of-bounds Write •

CVE-2020-12399 – nss: Timing attack on DSA signature generation
https://notcve.org/view.php?id=CVE-2020-12399
05 Jun 2020 — NSS has shown timing differences when performing DSA signatures, which was exploitable and could eventually leak private keys. This vulnerability affects Thunderbird < 68.9.0, Firefox < 77, and Firefox ESR < 68.9. NSS ha mostrado diferencias de sincronización cuando se llevan a cabo firmas DSA, que fue explotable y eventualmente podría filtrar claves privadas. Esta vulnerabilidad afecta a Thunderbird versiones anteriores a 68.9.0, Firefox versiones anteriores a 77 y Firefox ESR versiones anteriores a 68.9 A... • https://bugzilla.mozilla.org/show_bug.cgi?id=1631576 • CWE-203: Observable Discrepancy CWE-327: Use of a Broken or Risky Cryptographic Algorithm •

CVE-2020-12407 – Gentoo Linux Security Advisory 202006-07
https://notcve.org/view.php?id=CVE-2020-12407
05 Jun 2020 — Mozilla Developer Nicolas Silva found that when using WebRender, Firefox would under certain conditions leak arbitrary GPU memory to the visible screen. The leaked memory content was visible to the user, but not observable from web content. This vulnerability affects Firefox < 77. El desarrollador de Mozilla, Nicolas Silva, detectó que cuando usaba WebRender, Firefox, bajo determinadas condiciones, filtra memoria arbitraria de la GPU hacia la pantalla visible. El contenido de la memoria filtrada era visible... • https://bugzilla.mozilla.org/show_bug.cgi?id=1637112 • CWE-125: Out-of-bounds Read •

CVE-2020-12408 – Gentoo Linux Security Advisory 202006-07
https://notcve.org/view.php?id=CVE-2020-12408
05 Jun 2020 — When browsing a document hosted on an IP address, an attacker could insert certain characters to flip domain and path information in the address bar. This vulnerability affects Firefox < 77. Al explorar un documento alojado en una dirección IP, un atacante podría insertar determinados caracteres para voltear una información de dominio y ruta en la barra de direcciones. Esta vulnerabilidad afecta a Firefox versiones anteriores a 77 Multiple security issues were discovered in Firefox. If a user were tricked i... • https://bugzilla.mozilla.org/show_bug.cgi?id=1623888 •

CVE-2020-12405 – Mozilla: Use-after-free in SharedWorkerService
https://notcve.org/view.php?id=CVE-2020-12405
03 Jun 2020 — When browsing a malicious page, a race condition in our SharedWorkerService could occur and lead to a potentially exploitable crash. This vulnerability affects Thunderbird < 68.9.0, Firefox < 77, and Firefox ESR < 68.9. Cuando se navega una página maliciosa, podría ocurrir una condición de carrera en nuestro SharedWorkerService y conllevar a un bloqueo potencialmente explotable. Esta vulnerabilidad afecta a Thunderbird versiones anteriores a 68.9.0, Firefox versiones anteriores a 77 y Firefox ESR versiones ... • https://bugzilla.mozilla.org/show_bug.cgi?id=1631618 • CWE-362: Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') CWE-416: Use After Free •

CVE-2020-12410 – Mozilla: Memory safety bugs fixed in Firefox 77 and Firefox ESR 68.9
https://notcve.org/view.php?id=CVE-2020-12410
03 Jun 2020 — Mozilla developers reported memory safety bugs present in Firefox 76 and Firefox ESR 68.8. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Thunderbird < 68.9.0, Firefox < 77, and Firefox ESR < 68.9. Los desarrolladores de Mozilla reportaron bugs de seguridad de la memoria presentes en Firefox versión 76 y Firefox ESR versión 68.8. Algunos de estos bugs mostraron evidencia ... • https://bugzilla.mozilla.org/buglist.cgi?bug_id=1619305%2C1632717 • CWE-120: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') CWE-787: Out-of-bounds Write •

CVE-2020-12406 – Mozilla: JavaScript Type confusion with NativeTypes
https://notcve.org/view.php?id=CVE-2020-12406
03 Jun 2020 — Mozilla Developer Iain Ireland discovered a missing type check during unboxed objects removal, resulting in a crash. We presume that with enough effort that it could be exploited to run arbitrary code. This vulnerability affects Thunderbird < 68.9.0, Firefox < 77, and Firefox ESR < 68.9. El desarrollador de Mozilla, Iain Ireland, detectó una falta de un tipo comprobación durante la eliminación de objetos sin caja, resultando en un bloqueo. Presumimos que con un esfuerzo suficiente podría ser explotado para ... • https://bugzilla.mozilla.org/show_bug.cgi?id=1639590 • CWE-345: Insufficient Verification of Data Authenticity CWE-843: Access of Resource Using Incompatible Type ('Type Confusion') •