CVE-2020-6822

CVSS v3.1 8.8 (High)
88% Progress
CVSS v2.0 6.8 (Medium)
68% Progress
EPSS 0.31 % (70th)
0.31% Progress
Affected Products 3
Advisories 30

On 32-bit builds, an out of bounds write could have occurred when processing an image larger than 4 GB in <code>GMPDecodeData</code>. It is possible that with enough effort this could have been exploited to run arbitrary code. This vulnerability affects Thunderbird < 68.7.0, Firefox ESR < 68.7, and Firefox < 75.

Weaknesses
CWE-787
Out-of-bounds Write
CVE Status
PUBLISHED
CNA
Mozilla Corporation
Published Date
2020-04-24 16:15:13
(4 years ago)
Updated Date
2020-05-01 13:44:38
(4 years ago)

Affected Products

Loading...
Loading...

Configuration #1

    CPE23 From Up To
  Mozilla Firefox prior 75.0 version cpe:2.3:a:mozilla:firefox < 75.0
  Mozilla Firefox Esr prior 68.7.0 version cpe:2.3:a:mozilla:firefox_esr < 68.7.0
  Mozilla Thunderbird prior 68.7.0 version cpe:2.3:a:mozilla:thunderbird < 68.7.0
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...