Multiple security issues were discovered in Firefox. If a user were tricked into opening a specially crafted website, an attacker could potentially exploit these to cause a denial of service, obtain sensitive information, bypass the CSS sanitizer, bypass security restrictions, spoof the URL bar, or execute arbitrary code. (CVE-2020-16042, CVE-2020-26971, CVE-2020-26972, CVE-2020-26793, CVE-2020-26974, CVE-2020-26976, CVE-2020-26978, CVE-2020-26979, CVE-2020-35113, CVE-2020-35114)
It was discovered that the proxy.onRequest API did not catch view-source URLs. If a user were tricked in to installing an extension with the proxy permission and opening View Source, an attacker could potentially exploit this to obtain sensitive information. (CVE-2020-35111)
{ "availability": "No subscription required", "binaries": [ { "binary_version": "84.0+build3-0ubuntu0.16.04.1", "binary_name": "firefox" }, { "binary_version": "84.0+build3-0ubuntu0.16.04.1", "binary_name": "firefox-dev" }, { "binary_version": "84.0+build3-0ubuntu0.16.04.1", "binary_name": "firefox-geckodriver" }, { "binary_version": "84.0+build3-0ubuntu0.16.04.1", "binary_name": "firefox-mozsymbols" } ] }
{ "availability": "No subscription required", "binaries": [ { "binary_version": "84.0+build3-0ubuntu0.18.04.1", "binary_name": "firefox" }, { "binary_version": "84.0+build3-0ubuntu0.18.04.1", "binary_name": "firefox-dev" }, { "binary_version": "84.0+build3-0ubuntu0.18.04.1", "binary_name": "firefox-geckodriver" }, { "binary_version": "84.0+build3-0ubuntu0.18.04.1", "binary_name": "firefox-mozsymbols" } ] }
{ "availability": "No subscription required", "binaries": [ { "binary_version": "84.0+build3-0ubuntu0.20.04.1", "binary_name": "firefox" }, { "binary_version": "84.0+build3-0ubuntu0.20.04.1", "binary_name": "firefox-dev" }, { "binary_version": "84.0+build3-0ubuntu0.20.04.1", "binary_name": "firefox-geckodriver" }, { "binary_version": "84.0+build3-0ubuntu0.20.04.1", "binary_name": "firefox-mozsymbols" } ] }