CVE-2020-15656

HIGH

Firefox < 79.0 and Firefox ESR < 78.1 - Type Confusion in JIT Optimizations

Title source: llm
STIX 2.1

Description

JIT optimizations involving the Javascript arguments object could confuse later optimizations. This risk was already mitigated by various precautions in the code, resulting in this bug rated at only moderate severity. This vulnerability affects Firefox ESR < 78.1, Firefox < 79, and Thunderbird < 78.1.

References (6)

Core 6
Core References
Issue Tracking, Permissions Required, Vendor Advisory x_refsource_misc
https://bugzilla.mozilla.org/show_bug.cgi?id=1647293
Third Party Advisory vendor-advisory x_refsource_suse
http://lists.opensuse.org/opensuse-security-announce/2020-08/msg00025.html
Third Party Advisory vendor-advisory x_refsource_ubuntu
https://usn.ubuntu.com/4443-1/

Scores

CVSS v3 8.8
EPSS 0.0151
EPSS Percentile 71.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Details

CWE
CWE-843
Status published
Products (7)
canonical/ubuntu_linux 16.04
canonical/ubuntu_linux 18.04
canonical/ubuntu_linux 20.04
mozilla/firefox < 79.0
mozilla/firefox_esr < 78.1
mozilla/thunderbird < 78.1
opensuse/leap 15.2
Published Aug 10, 2020
Tracked Since Feb 18, 2026