CVE-2020-15670 describes memory safety bugs in Mozilla Firefox, Firefox ESR, Thunderbird, and Firefox for Android versions prior to their respective 80/78.2 releases. These bugs could lead to memory corruption, potentially allowing an attacker to execute arbitrary code with sufficient effort. Rated 8.8 HIGH on CVSS, this vulnerability is network-exploitable with low attack complexity and user interaction required, posing high impacts to confidentiality, integrity, and availability. There is no evidence of active exploitation, public exploit code, or significant community discussion, and it is not listed on the CISA KEV catalog.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 80.0CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox:*:*:*:*:*:-:*:* | ||
< 80.0CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox:*:*:*:*:*:android:*:* | ||
< 78.2CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox_esr:*:*:*:*:*:*:*:* | ||
< 78.2CPE matchmatch criteria | cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.