Search CVE reports


Toggle filters

1261 – 1270 of 3249 results


CVE-2020-15682

Low priority

Some fixes available 11 of 17

When a link to an external protocol was clicked, a prompt was presented that allowed the user to choose what application to open it in. An attacker could induce that prompt to be associated with an origin they didn't control,...

5 affected packages

firefox, mozjs38, mozjs52, mozjs60, mozjs68

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox Fixed Fixed Fixed Fixed
mozjs38 Not in release Not in release Not in release Ignored
mozjs52 Not in release Not in release Ignored Ignored
mozjs60 Not in release Not in release Not in release Not in release
mozjs68 Not in release Not in release Ignored Not in release
Show less packages

CVE-2020-15681

Medium priority

Some fixes available 11 of 17

When multiple WASM threads had a reference to a module, and were looking up exported functions, one WASM thread could have overwritten another's entry in a shared stub table, resulting in a potentially exploitable crash....

5 affected packages

firefox, mozjs38, mozjs52, mozjs60, mozjs68

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox Fixed Fixed Fixed Fixed
mozjs38 Not in release Not in release Not in release Ignored
mozjs52 Not in release Not in release Ignored Ignored
mozjs60 Not in release Not in release Not in release Not in release
mozjs68 Not in release Not in release Ignored Not in release
Show less packages

CVE-2020-15680

Medium priority

Some fixes available 11 of 17

If a valid external protocol handler was referenced in an image tag, the resulting broken image size could be distinguished from a broken image size of a non-existent protocol handler. This allowed an attacker to successfully...

5 affected packages

firefox, mozjs38, mozjs52, mozjs60, mozjs68

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox Fixed Fixed Fixed Fixed
mozjs38 Not in release Not in release Not in release Ignored
mozjs52 Not in release Not in release Ignored Ignored
mozjs60 Not in release Not in release Not in release Not in release
mozjs68 Not in release Not in release Ignored Not in release
Show less packages

CVE-2020-15254

Medium priority

Some fixes available 15 of 31

Crossbeam is a set of tools for concurrent programming. In crossbeam-channel before version 0.4.4, the bounded channel incorrectly assumes that `Vec::from_iter` has allocated capacity that same as the number of iterator elements....

6 affected packages

rust-crossbeam, firefox, mozjs38, mozjs52, mozjs60, mozjs68

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
rust-crossbeam Needs evaluation Needs evaluation Needs evaluation Needs evaluation Not in release
firefox Fixed Fixed Fixed Fixed Fixed
mozjs38 Not in release Not in release Not in release Not in release Ignored
mozjs52 Not in release Not in release Not in release Ignored Ignored
mozjs60 Not in release Not in release Not in release Not in release Not in release
mozjs68 Not in release Not in release Not in release Ignored Not in release
Show less packages

CVE-2020-15999

High priority
Fixed

Heap buffer overflow in Freetype in Google Chrome prior to 86.0.4240.111 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

18 affected packages

android, chromium-browser, firefox, freetype, godot...

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
android Not in release Not in release Not in release Not in release
chromium-browser Not affected Not affected Not in release Fixed
firefox Not affected Not affected Not in release Not affected
freetype Fixed Fixed Fixed Fixed
godot Not affected Not affected Not affected Not in release
graphicsmagick Not affected Not affected Not affected Not affected
musescore Not in release Not in release Not affected Not affected
openjdk-12 Not in release Not in release Not in release Not in release
openjdk-13 Not in release Not in release Not affected Not in release
openjdk-15 Not in release Not in release Not in release Not in release
openjdk-lts Not affected Not affected Not affected Not affected
oxide-qt Not in release Not in release Not in release Not in release
paraview Not affected Not affected Not affected Not affected
qtbase-opensource-src Not affected Not affected Not affected Not affected
qtbase-opensource-src-gles Not affected Not affected Not affected Not in release
texlive-bin Not affected Not affected Not affected Not affected
texmaker Not affected Not affected Not affected Not affected
thunderbird Not affected Not affected Not in release Not affected
Show all 18 packages Show less packages

CVE-2020-15969

Medium priority

Some fixes available 23 of 29

Use after free in WebRTC in Google Chrome prior to 86.0.4240.75 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

7 affected packages

chromium-browser, firefox, mozjs38, mozjs52, mozjs60...

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
chromium-browser Not affected Not affected Not in release Fixed
firefox Fixed Fixed Fixed Fixed
mozjs38 Not in release Not in release Not in release Ignored
mozjs52 Not in release Not in release Ignored Ignored
mozjs60 Not in release Not in release Not in release Not in release
mozjs68 Not in release Not in release Ignored Not in release
thunderbird Fixed Fixed Fixed Fixed
Show all 7 packages Show less packages

CVE-2020-15669

Medium priority
Fixed

When aborting an operation, such as a fetch, an abort signal may be deleted while alerting the objects to be notified. This results in a use-after-free and we presume that with enough effort it could have been exploited to...

2 affected packages

firefox-esr, thunderbird

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox-esr Not in release Not in release Not in release
thunderbird Not affected Fixed Fixed
Show less packages

CVE-2020-15667

Low priority
Ignored

When processing a MAR update file, after the signature has been validated, an invalid name length could result in a heap overflow, leading to memory corruption and potentially arbitrary code execution. Within Firefox as released...

5 affected packages

firefox, mozjs38, mozjs52, mozjs60, mozjs68

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox Not affected Not affected Not in release Not affected
mozjs38 Not in release Not in release Not in release Ignored
mozjs52 Not in release Not in release Ignored Ignored
mozjs60 Not in release Not in release Not in release Not in release
mozjs68 Not in release Not in release Ignored Not in release
Show less packages

CVE-2020-15663

Medium priority
Not affected

If Firefox is installed to a user-writable directory, the Mozilla Maintenance Service would execute updater.exe from the install location with system privileges. Although the Mozilla Maintenance Service does ensure that...

2 affected packages

firefox, thunderbird

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox Not in release Not affected
thunderbird Not in release Not affected
Show less packages

CVE-2020-15678

Medium priority

Some fixes available 13 of 19

When recursing through graphical layers while scrolling, an iterator may have become invalid, resulting in a potential use-after-free. This occurs because the function APZCTreeManager::ComputeClippedCompositionBounds did not...

6 affected packages

firefox, mozjs38, mozjs52, mozjs60, mozjs68, thunderbird

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox Fixed Fixed Fixed Fixed
mozjs38 Not in release Not in release Not in release Ignored
mozjs52 Not in release Not in release Ignored Ignored
mozjs60 Not in release Not in release Not in release Not in release
mozjs68 Not in release Not in release Ignored Not in release
thunderbird Not affected Not affected Fixed Fixed
Show less packages