target entity

Firefox and Thunderbird

6 source-linked records in the current knowledge graph.

high

CVE-2019-11707: Mozilla Firefox and Thunderbird Type Confusion Vulnerability

Mozilla Firefox and Thunderbird contain a type confusion vulnerability that can occur when manipulating JavaScript objects due to issues in Array.pop, allowing for an exploitable crash. Required action: Apply updates per vendor instructions.

CVE-2019-11707EPSS 38.0%Firefox and ThunderbirdMozilla
CISA KEV ↗ · unattributed attribution · 1 IOC
high

CVE-2013-1690: Mozilla Firefox and Thunderbird Denial-of-Service Vulnerability

Mozilla Firefox and Thunderbird do not properly handle onreadystatechange events in conjunction with page reloading, which allows remote attackers to cause a denial-of-service (DoS) or possibly execute malicious code via a crafted web site. Required action: Apply updates per vendor instructions.

CVE-2013-1690EPSS 69.0%Firefox and ThunderbirdMozilla
CISA KEV ↗ · unattributed attribution
high

CVE-2020-6819: Mozilla Firefox And Thunderbird Use-After-Free Vulnerability

Mozilla Firefox and Thunderbird contain a race condition vulnerability when running the nsDocShell destructor under certain conditions. The race condition creates a use-after-free vulnerability, causing unspecified impacts. Required action: Apply updates per vendor instructions.

CVE-2020-6819EPSS 3.0%Firefox and ThunderbirdMozilla
CISA KEV ↗ · unattributed attribution
high

CVE-2020-6820: Mozilla Firefox And Thunderbird Use-After-Free Vulnerability

Mozilla Firefox and Thunderbird contain a race condition vulnerability when handling a ReadableStream under certain conditions. The race condition creates a use-after-free vulnerability, causing unspecified impacts. Required action: Apply updates per vendor instructions.

CVE-2020-6820EPSS 6.3%Firefox and ThunderbirdMozilla
CISA KEV ↗ · unattributed attribution