Get a Pentest and security assessment of your IT network.

2021-current

CVE-2020-26954 – When accepting a malicious intent from other installed apps, Firefox for

When accepting a malicious intent from other installed apps, Firefox for Android accepted manifests from arbitrary file paths and allowed declaring webapp manifests for other origins. This could be used to gain fullscreen access for UI spoofing and could also lead to cross-origin attacks on targeted websites. *Note: This issue only affected Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 83.   Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-26954 Reference (s):

  • https://www.mozilla.org/security/advisories/mfsa2020-50/
  • URL: https://www.mozilla.org/security/advisories/mfsa2020-50/
  • https://bugzilla.mozilla.org/show_bug.cgi?id=1657026
  • URL: https://bugzilla.mozilla.org/show_bug.cgi?id=1657026
Related posts
2021-current

CVE-2004-1715 - Directory traversal vulnerability in MIMEsweeper for Web before 5.0.4 all

2021-current

CVE-2014-5418 - GE Multilink ML800, ML1200, ML1600, and ML2400 switches with firmware 4.2

2021-current

CVE-2019-7127 - Adobe Acrobat and Reader versions 2019.010.20098 and earlier, 2019.010.20

2021-current

CVE-2020-10978 - GitLab EE/CE 8.11 to 12.9 is leaking information on Issues opened in a pu