Get a Pentest and security assessment of your IT network.

2021-current

CVE-2020-15676 – Firefox sometimes ran the onload handler for SVG elements that the DOM sa

Firefox sometimes ran the onload handler for SVG elements that the DOM sanitizer decided to remove, resulting in JavaScript being executed after pasting attacker-controlled data into a contenteditable element. This vulnerability affects Firefox < 81, Thunderbird < 78.3, and Firefox ESR < 78.3.   Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-15676 Reference (s):

  • DEBIAN:DSA-4770
  • URL: https://www.debian.org/security/2020/dsa-4770
  • GENTOO:GLSA-202010-02
  • URL: https://security.gentoo.org/glsa/202010-02
  • https://bugzilla.mozilla.org/show_bug.cgi?id=1646140
Related posts
2021-current

CVE-2004-1715 - Directory traversal vulnerability in MIMEsweeper for Web before 5.0.4 all

2021-current

CVE-2014-6594 - Unspecified vulnerability in the Oracle iLearning component in Oracle iLe

2021-current

CVE-2019-8457 - SQLite3 from 3.6.0 to and including 3.27.2 is vulnerable to heap out-of-b

2021-current

CVE-2020-12257 - rConfig 3.9.4 is vulnerable to cross-site request forgery (CSRF) because