Description
Multiple vulnerabilities were found in Mozilla Thunderbird. Malicious users can exploit these vulnerabilities to cause denial of service, bypass security restrictions, obtain sensitive information.
Below is a complete list of vulnerabilities:
- Memory corruption vulnerability on JavaScript Objects on ARM64 platforms can be exploited to potentially cause denial of service.
- SB vulnerability in add-on updates can be exploited to bypass security restrictions.
- Use after free vulnerability in a pointer can be exploited to potentially cause denial of service.
- Information disclosure vulnerbaility in URL object can be exploited to obtain sensitive information.
- Use after free vulnerability in nsGlobalWindowInner component can be exploited to potentially cause denial of service.
- Information disclosure vulnerbaility in Microsoft Exchange can be exploited remotely to obtain sensitive information.
Original advisories
Related products
CVE list
- CVE-2020-12417 critical
- CVE-2020-12421 warning
- CVE-2020-12420 critical
- CVE-2020-12418 warning
- CVE-2020-12419 critical
- CVE-2020-15646 warning
Read more
Find out the statistics of the vulnerabilities spreading in your region on statistics.securelist.com
Found an inaccuracy in the description of this vulnerability? Let us know!