Multiple Vulnerabilities in Mozilla Firefox
Software Affected
• Firefox versions prior to 73
• Firefox ESR versions prior to 68.5
Overview
Multiple vulnerabilities have been reported in Mozilla Firefox which could allow a remote attacker to execute arbitrary code or
bypass security restrictions on a targeted system.
Description
1. Out-of-bounds write ( CVE-2020-6796 )
2. Improper access control ( CVE-2020-6797 )
3. JavascriptInjection ( CVE-2020-6798 )
4. Arbitrary code execution ( CVE-2020-6799 )
5. Memory corruption ( CVE-2020-6800 CVE-2020-6801 )
• Firefox versions prior to 73
• Firefox ESR versions prior to 68.5
Overview
Multiple vulnerabilities have been reported in Mozilla Firefox which could allow a remote attacker to execute arbitrary code or
bypass security restrictions on a targeted system.
Description
1. Out-of-bounds write ( CVE-2020-6796 )
- This vulnerability exists in Mozilla Firefox due to an out-of-bounds write error. A remote attacker could exploit this vulnerability by persuading a user to visit a specially crafted website.
- Successful exploitation of this vulnerability could allow the attacker to execute arbitrary code on the targeted system.
2. Improper access control ( CVE-2020-6797 )
- This vulnerability exists in Mozilla Firefox on Max OSX due to improper access restrictions imposed on extensions that are granted "downloads. open" permission. A remote attacker could exploit this vulnerability by persuading a user to install a crafted extension.
- Successful exploitation of this vulnerability could allow the attacker to open arbitrary applications on the targeted system.
3. JavascriptInjection ( CVE-2020-6798 )
- This vulnerability exists in Mozilla Firefox due to improper input validation when parsing a <template> tag. A remote attacker could exploit this vulnerability by persuading a user to visit a specially crafted website.
- Successful exploitation of this vulnerability could allow the attacker to perform cross-site scripting attacks on the targeted system.
4. Arbitrary code execution ( CVE-2020-6799 )
- This vulnerability exists in Mozilla Firefox on Windows due to improper input validation. A remote attacker could exploit this vulnerability by persuading a user to open crafted PDF links on a targeted system.
- Successful exploitation of this vulnerability could allow the attacker to execute arbitrary code on the targeted system.
5. Memory corruption ( CVE-2020-6800 CVE-2020-6801 )
Comments
Post a Comment