CVE-2020-6820 is a high-severity use-after-free vulnerability affecting Mozilla Firefox, Firefox ESR, and Thunderbird versions prior to 74.0.1, 68.6.1, and 68.7.0 respectively. This flaw arises from a race condition during ReadableStream handling, which can lead to remote code execution. With a CVSS score of 8.1 (HIGH), it presents a significant risk due to its network-based attack vector, high impact on confidentiality, integrity, and availability, and low attack complexity. The vulnerability is actively exploited in the wild, as confirmed by its presence in the CISA KEV catalog. While no public exploit code is available via Metasploit, Nuclei, or ExploitDB, its active exploitation underscores the urgency of patching. Despite limited community discussion, the vulnerability has received significant media coverage, indicating its critical nature and the awareness of its active exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 68.6.1CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox:*:*:*:*:esr:*:*:* | ||
< 74.0.1CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox:*:*:*:*:-:*:*:* | ||
< 68.7.0CPE matchmatch criteria | cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.