CVE-2020-6821 Vulnerability Details

  /     /     /  

CVE-2020-6821 Metadata Quick Info

CVE Published: 24/04/2020 | CVE Updated: 04/08/2024 | CVE Year: 2020
Source: mozilla | Vendor: Mozilla | Product: Thunderbird
Status : PUBLISHED

CVE-2020-6821 Description

When reading from areas partially or fully outside the source resource with WebGL\'s copyTexSubImage method, the specification requires the returned values be zero. Previously, this memory was uninitialized, leading to potentially sensitive data disclosure. This vulnerability affects Thunderbird < 68.7.0, Firefox ESR < 68.7, and Firefox < 75.

Metrics

CVSS Version: 3.1 | Base Score: n/a
Vector: n/a

l➤ Exploitability Metrics:
    Attack Vector (AV)*
    Attack Complexity (AC)*
    Privileges Required (PR)*
    User Interaction (UI)*
    Scope (S)*

l➤ Impact Metrics:
    Confidentiality Impact (C)*
    Integrity Impact (I)*
    Availability Impact (A)*

Weakness Enumeration (CWE)

CWE-ID:
CWE Name: Uninitialized memory could be read when using the WebGL copyTexSubImage method
Source: Mozilla

Common Attack Pattern Enumeration and Classification (CAPEC)

CAPEC-ID:
CAPEC Description:


Source: NVD (National Vulnerability Database).