CVE-2020-12387

CVSS v3.1 8.1 (High)
81% Progress
CVSS v2.0 6.8 (Medium)
68% Progress
EPSS 1.02 % (84th)
1.02% Progress
Affected Products 3
Advisories 31

A race condition when running shutdown code for Web Worker led to a use-after-free vulnerability. This resulted in a potentially exploitable crash. This vulnerability affects Firefox ESR < 68.8, Firefox < 76, and Thunderbird < 68.8.0.

Weaknesses
CWE-362
Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CWE-416
Use After Free
CVE Status
PUBLISHED
CNA
Mozilla Corporation
Published Date
2020-05-26 18:15:10
(4 years ago)
Updated Date
2021-12-14 20:23:28
(2 years ago)

Affected Products

Loading...
Loading...
Loading...

Configuration #1

    CPE23 From Up To
  Mozilla Firefox prior 76.0 version cpe:2.3:a:mozilla:firefox < 76.0
  Mozilla Firefox Esr prior 68.8.0 version cpe:2.3:a:mozilla:firefox_esr < 68.8.0
  Mozilla Thunderbird prior 68.8.0 version cpe:2.3:a:mozilla:thunderbird < 68.8.0
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...