ZeroHour

CVE-2020-12405

PoC
CVSS 3.1
5.3 medium
EPSS
1%p70
Published
()
Modified
Description

When browsing a malicious page, a race condition in our SharedWorkerService could occur and lead to a potentially exploitable crash. This vulnerability affects Thunderbird < 68.9.0, Firefox < 77, and Firefox ESR < 68.9.

Vendors
mozillacanonical
Products
firefox, firefox esr, thunderbird, ubuntu linux
Weakness
CWE-362, CWE-416
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H

In the news