CVE-2020-26966
published 2020-12-09CVE-2020-26966: Searching for a single word from the address bar caused an mDNS request to be sent on the local network searching for a hostname consisting of that string…
PriorityP430medium6.5CVSS 3.1
AVNACLPRNUIRSUCHINAN
EPSS
1.34%
68.1th percentile
Searching for a single word from the address bar caused an mDNS request to be sent on the local network searching for a hostname consisting of that string; resulting in an information leak. *Note: This issue only affected Windows operating systems. Other operating systems are unaffected.*. This vulnerability affects Firefox < 83, Firefox ESR < 78.5, and Thunderbird < 78.5.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | firefox | — | — |
| debian | firefox-esr | — | — |
| debian | thunderbird | — | — |
| mozilla | firefox | < 83 | 83 |
| mozilla | firefox | < 83.0 | 83.0 |
| mozilla | firefox | — | — |
| mozilla | firefox_esr | < 78.5 | 78.5 |
| mozilla | thunderbird | < 78.5 | 78.5 |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
osv6.5MEDIUM
vendor_debian6.5LOW
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-c627-2gcf-x56f: Searching for a single word from the address bar caused an mDNS request to be sent on the local network searching for a hostname consisting of that st
ghsa_unreviewed·2022-05-24
CVE-2020-26966 [MEDIUM] GHSA-c627-2gcf-x56f: Searching for a single word from the address bar caused an mDNS request to be sent on the local network searching for a hostname consisting of that st
Searching for a single word from the address bar caused an mDNS request to be sent on the local network searching for a hostname consisting of that string; resulting in an information leak. *Note: This issue only affected Windows operating systems. Other operating systems are unaffected.*. This vulnerability affects Firefox < 83, Firefox ESR < 78.5, and Thunderbird < 78.5.
OSV
CVE-2020-26966: Searching for a single word from the address bar caused an mDNS request to be sent on the local network searching for a hostname consisting of that st
osv·2020-12-09·CVSS 6.5
CVE-2020-26966 [MEDIUM] CVE-2020-26966: Searching for a single word from the address bar caused an mDNS request to be sent on the local network searching for a hostname consisting of that st
Searching for a single word from the address bar caused an mDNS request to be sent on the local network searching for a hostname consisting of that string; resulting in an information leak. *Note: This issue only affected Windows operating systems. Other operating systems are unaffected.*. This vulnerability affects Firefox < 83, Firefox ESR < 78.5, and Thunderbird < 78.5.
Red Hat
Mozilla: Single-word search queries were also broadcast to local network
vendor_redhat·2020-11-17·CVSS 6.5
CVE-2020-26966 [MEDIUM] CWE-200 Mozilla: Single-word search queries were also broadcast to local network
Mozilla: Single-word search queries were also broadcast to local network
Searching for a single word from the address bar caused an mDNS request to be sent on the local network searching for a hostname consisting of that string; resulting in an information leak. *Note: This issue only affected Windows operating systems. Other operating systems are unaffected.*. This vulnerability affects Firefox < 83, Firefox ESR < 78.5, and Thunderbird < 78.5.
Package: firefox (Red Hat Enterprise Linux 5) - Not affected
Package: firefox (Red Hat Enterprise Linux 6) - Not affected
Package: firefox (Red Hat Enterprise Linux 7) - Not affected
Package: firefox (Red Hat Enterprise Linux 8) - Not affected
Debian
CVE-2020-26966: firefox - Searching for a single word from the address bar caused an mDNS request to be se...
vendor_debian·2020·CVSS 6.5
CVE-2020-26966 [MEDIUM] CVE-2020-26966: firefox - Searching for a single word from the address bar caused an mDNS request to be se...
Searching for a single word from the address bar caused an mDNS request to be sent on the local network searching for a hostname consisting of that string; resulting in an information leak. *Note: This issue only affected Windows operating systems. Other operating systems are unaffected.*. This vulnerability affects Firefox < 83, Firefox ESR < 78.5, and Thunderbird < 78.5.
Scope: local
sid: resolved
Mozilla
Mozilla Foundation Security Advisory 2020-51: CVE-2020-26966
vendor_mozilla·CVSS 6.5
CVE-2020-26966 [MEDIUM] Mozilla Foundation Security Advisory 2020-51: CVE-2020-26966
Mozilla Foundation Security Advisory 2020-51
CVE: CVE-2020-26966
Product: Firefox ESR
Impact: high
Fixed in: Firefox ESR 78.5
Mozilla
Mozilla Foundation Security Advisory 2020-50: CVE-2020-26966
vendor_mozilla·CVSS 6.5
CVE-2020-26966 [MEDIUM] Mozilla Foundation Security Advisory 2020-50: CVE-2020-26966
Mozilla Foundation Security Advisory 2020-50
CVE: CVE-2020-26966
Product: Firefox
Impact: high
Fixed in: Firefox 83
Mozilla
Mozilla Foundation Security Advisory 2020-52: CVE-2020-26966
vendor_mozilla·CVSS 6.5
CVE-2020-26966 [MEDIUM] Mozilla Foundation Security Advisory 2020-52: CVE-2020-26966
Mozilla Foundation Security Advisory 2020-52
CVE: CVE-2020-26966
Product: Thunderbird
Impact: high
Fixed in: Thunderbird 78.5
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://bugzilla.mozilla.org/show_bug.cgi?id=1663571https://www.mozilla.org/security/advisories/mfsa2020-50/https://www.mozilla.org/security/advisories/mfsa2020-51/https://www.mozilla.org/security/advisories/mfsa2020-52/https://bugzilla.mozilla.org/show_bug.cgi?id=1663571https://www.mozilla.org/security/advisories/mfsa2020-50/https://www.mozilla.org/security/advisories/mfsa2020-51/https://www.mozilla.org/security/advisories/mfsa2020-52/
2020-12-09
Published