CVE-2020-15673

HIGH

Firefox < 81.0 and Firefox ESR < 78.3 - Use-After-Free

Title source: llm
STIX 2.1

Description

Mozilla developers reported memory safety bugs present in Firefox 80 and Firefox ESR 78.2. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 81, Thunderbird < 78.3, and Firefox ESR < 78.3.

References (9)

Core 9
Core References
Release Notes, Vendor Advisory x_refsource_misc
https://www.mozilla.org/security/advisories/mfsa2020-43/
Release Notes, Vendor Advisory x_refsource_misc
https://www.mozilla.org/security/advisories/mfsa2020-44/
Release Notes, Vendor Advisory x_refsource_misc
https://www.mozilla.org/security/advisories/mfsa2020-42/
Broken Link, Issue Tracking, Vendor Advisory x_refsource_misc
https://bugzilla.mozilla.org/buglist.cgi?bug_id=1648493%2C1660800
Third Party Advisory vendor-advisory x_refsource_debian
https://www.debian.org/security/2020/dsa-4770
Mailing List, Third Party Advisory mailing-list x_refsource_mlist
https://lists.debian.org/debian-lts-announce/2020/10/msg00020.html
Third Party Advisory vendor-advisory x_refsource_gentoo
https://security.gentoo.org/glsa/202010-02
Mailing List, Third Party Advisory vendor-advisory x_refsource_suse
http://lists.opensuse.org/opensuse-security-announce/2020-10/msg00074.html
Mailing List, Third Party Advisory vendor-advisory x_refsource_suse
http://lists.opensuse.org/opensuse-security-announce/2020-10/msg00077.html

Scores

CVSS v3 8.8
EPSS 0.0087
EPSS Percentile 75.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Details

CWE
CWE-416
Status published
Products (7)
debian/debian_linux 9.0
debian/debian_linux 10.0
mozilla/firefox < 81.0
mozilla/firefox_esr < 78.3
mozilla/thunderbird < 78.3
opensuse/leap 15.1
opensuse/leap 15.2
Published Oct 01, 2020
Tracked Since Feb 18, 2026