Multiple Vulnerabilities in Mozilla Firefox

Software Affected
• Firefox versions prior to 73
• Firefox ESR versions prior to 68.5

Overview
Multiple vulnerabilities have been reported  in  Mozilla Firefox which could allow a remote attacker to execute arbitrary code or
bypass security restrictions on a targeted system.

Description
1. Out-of-bounds write ( CVE-2020-6796 )

  • This vulnerability exists in  Mozilla Firefox due to an out-of-bounds write error. A remote attacker could exploit this vulnerability by persuading a user to visit a specially crafted website.
  • Successful exploitation of this vulnerability could allow the attacker to execute arbitrary code on the targeted system.

2. Improper access control  ( CVE-2020-6797 )

  • This vulnerability exists in  Mozilla Firefox on Max OSX due to improper access restrictions imposed on extensions that are granted "downloads. open" permission. A remote attacker could exploit this vulnerability by persuading a user to install a crafted extension.
  • Successful exploitation of this vulnerability could allow the attacker to open arbitrary applications on the targeted system.

3. JavascriptInjection  ( CVE-2020-6798 )
  • This vulnerability exists in  Mozilla Firefox due to improper input validation when parsing a <template> tag. A remote attacker could exploit this vulnerability by persuading a user to visit a specially crafted website.
  • Successful exploitation of this vulnerability could allow the attacker to perform cross-site scripting attacks on the targeted system.

4. Arbitrary code execution  ( CVE-2020-6799 )
  • This vulnerability exists in  Mozilla Firefox on Windows due to improper input validation. A remote attacker could exploit this vulnerability by persuading a user to open crafted PDF links on a targeted system.
  • Successful exploitation of this vulnerability could allow the attacker to execute arbitrary code on the targeted system.

5. Memory corruption  ( CVE-2020-6800 CVE-2020-6801 )

Comments

Popular posts from this blog

CAREER TECHNOLOGY CYBER SECURITY INDIA PVT LTD.

Some Dark web Links

Cyber Security Audits