CVE-2020-12406

high
New! CVE Severity Now Using CVSS v3

The calculated severity for CVEs has been updated to use CVSS v3 by default. CVEs that do not have a CVSS v3 score will fall back CVSS v2 for calculating severity. Severity display preferences can be toggled in the settings dropdown.

Description

Mozilla Developer Iain Ireland discovered a missing type check during unboxed objects removal, resulting in a crash. We presume that with enough effort that it could be exploited to run arbitrary code. This vulnerability affects Thunderbird < 68.9.0, Firefox < 77, and Firefox ESR < 68.9.

References

https://bugzilla.mozilla.org/show_bug.cgi?id=1639590

https://usn.ubuntu.com/4421-1/

https://www.mozilla.org/security/advisories/mfsa2020-20/

https://www.mozilla.org/security/advisories/mfsa2020-21/

https://www.mozilla.org/security/advisories/mfsa2020-22/

Details

Source: MITRE

Published: 2020-07-09

Updated: 2020-07-22

Type: CWE-345

Risk Information

CVSS v2

Base Score: 9.3

Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Impact Score: 10

Exploitability Score: 8.6

Severity: HIGH

CVSS v3

Base Score: 8.8

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Impact Score: 5.9

Exploitability Score: 2.8

Severity: HIGH

Tenable Plugins

View all (47 total)

IDNameProductFamilySeverity
150602SUSE SLES11 Security Update : MozillaFirefox (SUSE-SU-2020:14389-1)NessusSuSE Local Security Checks
high
147407NewStart CGSL MAIN 4.06 : firefox Multiple Vulnerabilities (NS-SA-2021-0004)NessusNewStart CGSL Local Security Checks
critical
147312NewStart CGSL MAIN 4.06 : thunderbird Multiple Vulnerabilities (NS-SA-2021-0002)NessusNewStart CGSL Local Security Checks
critical
146029CentOS 8 : firefox (CESA-2020:2379)NessusCentOS Local Security Checks
high
145956CentOS 8 : thunderbird (CESA-2020:2614)NessusCentOS Local Security Checks
high
144001NewStart CGSL CORE 5.04 / MAIN 5.04 : thunderbird Multiple Vulnerabilities (NS-SA-2020-0083)NessusNewStart CGSL Local Security Checks
high
143928NewStart CGSL CORE 5.04 / MAIN 5.04 : firefox Multiple Vulnerabilities (NS-SA-2020-0064)NessusNewStart CGSL Local Security Checks
critical
143075RHEL 6 : firefox (RHSA-2020:2378)NessusRed Hat Local Security Checks
high
138677openSUSE Security Update : MozillaThunderbird (openSUSE-2020-799)NessusSuSE Local Security Checks
high
138628Amazon Linux 2 : thunderbird (ALAS-2020-1462)NessusAmazon Linux Local Security Checks
high
138326Ubuntu 16.04 LTS / 18.04 LTS / 19.10 / 20.04 : Thunderbird vulnerabilities (USN-4421-1)NessusUbuntu Local Security Checks
high
138201Oracle Linux 6 : thunderbird (ELSA-2020-2613)NessusOracle Linux Local Security Checks
high
137881RHEL 8 : firefox (RHSA-2020:2382)NessusRed Hat Local Security Checks
high
137768Oracle Linux 8 : thunderbird (ELSA-2020-2614)NessusOracle Linux Local Security Checks
high
137741Scientific Linux Security Update : thunderbird on SL7.x x86_64 (20200622)NessusScientific Linux Local Security Checks
high
137730CentOS 7 : thunderbird (CESA-2020:2615)NessusCentOS Local Security Checks
high
137729CentOS 6 : thunderbird (CESA-2020:2613)NessusCentOS Local Security Checks
high
137709RHEL 7 : thunderbird (RHSA-2020:2615)NessusRed Hat Local Security Checks
high
137704RHEL 8 : thunderbird (RHSA-2020:2614)NessusRed Hat Local Security Checks
high
137698Scientific Linux Security Update : thunderbird on SL6.x i386/x86_64 (20200619)NessusScientific Linux Local Security Checks
high
137696Oracle Linux 7 : thunderbird (ELSA-2020-2615)NessusOracle Linux Local Security Checks
high
137666RHEL 8 : thunderbird (RHSA-2020:2611)NessusRed Hat Local Security Checks
high
137665RHEL 6 : thunderbird (RHSA-2020:2613)NessusRed Hat Local Security Checks
high
137664RHEL 8 : thunderbird (RHSA-2020:2616)NessusRed Hat Local Security Checks
high
137596SUSE SLES12 Security Update : MozillaFirefox (SUSE-SU-2020:1563-1)NessusSuSE Local Security Checks
high
137594SUSE SLED15 / SLES15 Security Update : MozillaFirefox (SUSE-SU-2020:1556-1)NessusSuSE Local Security Checks
high
137456GLSA-202006-19 : Mozilla Thunderbird: Multiple vulnerabilitiesNessusGentoo Local Security Checks
high
137444GLSA-202006-07 : Mozilla Firefox: Multiple vulnerabilitiesNessusGentoo Local Security Checks
high
137417Debian DLA-2247-1 : thunderbird security updateNessusDebian Local Security Checks
high
137375Debian DSA-4702-1 : thunderbird - security updateNessusDebian Local Security Checks
high
137349openSUSE Security Update : MozillaFirefox (openSUSE-2020-789)NessusSuSE Local Security Checks
high
137284Debian DLA-2243-1 : firefox-esr security update NessusDebian Local Security Checks
high
137221Oracle Linux 7 : firefox (ELSA-2020-2381)NessusOracle Linux Local Security Checks
high
137220Oracle Linux 8 : firefox (ELSA-2020-2379)NessusOracle Linux Local Security Checks
high
137179Ubuntu 16.04 LTS / 18.04 LTS / 19.10 / 20.04 : firefox vulnerabilities (USN-4383-1)NessusUbuntu Local Security Checks
high
137177Slackware 14.2 / current : mozilla-thunderbird (SSA:2020-156-01)NessusSlackware Local Security Checks
high
137176Scientific Linux Security Update : firefox on SL7.x x86_64 (20200603)NessusScientific Linux Local Security Checks
high
137175Scientific Linux Security Update : firefox on SL6.x i386/x86_64 (20200603)NessusScientific Linux Local Security Checks
high
137155Debian DSA-4695-1 : firefox-esr - security updateNessusDebian Local Security Checks
high
137150CentOS 7 : firefox (CESA-2020:2381)NessusCentOS Local Security Checks
high
137087Mozilla Thunderbird < 68.9.0NessusWindows
high
137086Mozilla Thunderbird < 68.9.0NessusMacOS X Local Security Checks
high
137083RHEL 7 : firefox (RHSA-2020:2381)NessusRed Hat Local Security Checks
high
137069RHEL 8 : firefox (RHSA-2020:2379)NessusRed Hat Local Security Checks
high
137066RHEL 8 : firefox (RHSA-2020:2380)NessusRed Hat Local Security Checks
high
137049Mozilla Firefox < 77.0NessusWindows
high
137048Mozilla Firefox < 77.0NessusMacOS X Local Security Checks
high