Mozilla developers and community members Tyson Smith and Christian Holler reported memory safety bugs present in Firefox 74 and Firefox ESR 68.6. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Thunderbird < 68.7.0, Firefox ESR < 68.7, and Firefox < 75.
https://bugzilla.mozilla.org/buglist.cgi?bug_id=1572541%2C1620193%2C1620203
https://usn.ubuntu.com/4335-1/
https://www.mozilla.org/security/advisories/mfsa2020-12/
Source: MITRE
Published: 2020-04-24
Updated: 2020-05-01
Type: CWE-119
Base Score: 7.5
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P
Impact Score: 6.4
Exploitability Score: 10
Severity: HIGH
Base Score: 9.8
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Impact Score: 5.9
Exploitability Score: 3.9
Severity: CRITICAL
OR
cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*
ID | Name | Product | Family | Severity |
---|---|---|---|---|
147407 | NewStart CGSL MAIN 4.06 : firefox Multiple Vulnerabilities (NS-SA-2021-0004) | Nessus | NewStart CGSL Local Security Checks | critical |
147312 | NewStart CGSL MAIN 4.06 : thunderbird Multiple Vulnerabilities (NS-SA-2021-0002) | Nessus | NewStart CGSL Local Security Checks | critical |
145974 | CentOS 8 : firefox (CESA-2020:1406) | Nessus | CentOS Local Security Checks | high |
145858 | CentOS 8 : thunderbird (CESA-2020:1495) | Nessus | CentOS Local Security Checks | high |
143979 | NewStart CGSL CORE 5.05 / MAIN 5.05 : thunderbird Multiple Vulnerabilities (NS-SA-2020-0093) | Nessus | NewStart CGSL Local Security Checks | critical |
143948 | NewStart CGSL CORE 5.05 / MAIN 5.05 : firefox Multiple Vulnerabilities (NS-SA-2020-0097) | Nessus | NewStart CGSL Local Security Checks | critical |
143928 | NewStart CGSL CORE 5.04 / MAIN 5.04 : firefox Multiple Vulnerabilities (NS-SA-2020-0064) | Nessus | NewStart CGSL Local Security Checks | critical |
143912 | NewStart CGSL CORE 5.04 / MAIN 5.04 : thunderbird Multiple Vulnerabilities (NS-SA-2020-0074) | Nessus | NewStart CGSL Local Security Checks | critical |
138776 | NewStart CGSL MAIN 6.01 : thunderbird Multiple Vulnerabilities (NS-SA-2020-0036) | Nessus | NewStart CGSL Local Security Checks | critical |
137246 | RHEL 8 : firefox (RHSA-2020:1406) | Nessus | Red Hat Local Security Checks | high |
137245 | RHEL 8 : firefox (RHSA-2020:1404) | Nessus | Red Hat Local Security Checks | high |
136752 | Amazon Linux 2 : thunderbird (ALAS-2020-1429) | Nessus | Amazon Linux Local Security Checks | critical |
136194 | CentOS 7 : thunderbird (CESA-2020:1489) | Nessus | CentOS Local Security Checks | high |
136017 | CentOS 6 : thunderbird (CESA-2020:1488) | Nessus | CentOS Local Security Checks | high |
136016 | CentOS 6 : firefox (CESA-2020:1429) | Nessus | CentOS Local Security Checks | high |
136007 | openSUSE Security Update : MozillaThunderbird (openSUSE-2020-544) | Nessus | SuSE Local Security Checks | high |
135947 | GLSA-202004-11 : Mozilla Firefox: Multiple vulnerabilities | Nessus | Gentoo Local Security Checks | high |
135896 | Ubuntu 16.04 LTS : Thunderbird vulnerabilities (USN-4335-1) | Nessus | Ubuntu Local Security Checks | high |
135845 | Scientific Linux Security Update : thunderbird on SL7.x x86_64 (20200416) | Nessus | Scientific Linux Local Security Checks | high |
135844 | Scientific Linux Security Update : firefox on SL7.x x86_64 (20200409) | Nessus | Scientific Linux Local Security Checks | high |
135747 | Oracle Linux 8 : thunderbird (ELSA-2020-1495) | Nessus | Oracle Linux Local Security Checks | high |
135716 | Scientific Linux Security Update : thunderbird on SL6.x i386/x86_64 (20200416) | Nessus | Scientific Linux Local Security Checks | high |
135715 | Oracle Linux 7 : thunderbird (ELSA-2020-1489) | Nessus | Oracle Linux Local Security Checks | high |
135692 | RHEL 8 : thunderbird (RHSA-2020:1495) | Nessus | Red Hat Local Security Checks | high |
135691 | RHEL 8 : thunderbird (RHSA-2020:1496) | Nessus | Red Hat Local Security Checks | high |
135687 | RHEL 6 : thunderbird (RHSA-2020:1488) | Nessus | Red Hat Local Security Checks | high |
135684 | RHEL 7 : thunderbird (RHSA-2020:1489) | Nessus | Red Hat Local Security Checks | high |
135578 | openSUSE Security Update : MozillaThunderbird (openSUSE-2020-520) | Nessus | SuSE Local Security Checks | high |
135575 | Scientific Linux Security Update : firefox on SL6.x i386/x86_64 (20200414) | Nessus | Scientific Linux Local Security Checks | high |
135495 | Debian DLA-2172-1 : thunderbird security update | Nessus | Debian Local Security Checks | high |
135455 | Ubuntu 18.04 LTS / 19.10 : Thunderbird vulnerabilities (USN-4328-1) | Nessus | Ubuntu Local Security Checks | high |
135446 | openSUSE Security Update : MozillaFirefox (openSUSE-2020-493) | Nessus | SuSE Local Security Checks | high |
135431 | Oracle Linux 7 : firefox (ELSA-2020-1420) | Nessus | Oracle Linux Local Security Checks | high |
135417 | Debian DSA-4656-1 : thunderbird - security update | Nessus | Debian Local Security Checks | high |
135415 | RHEL 6 : firefox (RHSA-2020:1429) | Nessus | Red Hat Local Security Checks | high |
135413 | Mozilla Thunderbird < 68.7.0 | Nessus | Windows | high |
135412 | Mozilla Thunderbird < 68.7.0 | Nessus | MacOS X Local Security Checks | high |
135397 | SUSE SLES12 Security Update : MozillaFirefox (SUSE-SU-2020:0978-1) | Nessus | SuSE Local Security Checks | high |
135396 | SUSE SLED15 / SLES15 Security Update : MozillaFirefox (SUSE-SU-2020:0971-1) | Nessus | SuSE Local Security Checks | high |
135380 | Oracle Linux 8 : firefox (ELSA-2020-1406) | Nessus | Oracle Linux Local Security Checks | high |
135366 | Debian DSA-4655-1 : firefox-esr - security update | Nessus | Debian Local Security Checks | high |
135363 | Debian DLA-2170-1 : firefox-esr security update | Nessus | Debian Local Security Checks | high |
135288 | RHEL 7 : firefox (RHSA-2020:1420) | Nessus | Red Hat Local Security Checks | high |
135284 | Ubuntu 16.04 LTS / 18.04 LTS / 19.10 : firefox vulnerabilities (USN-4323-1) | Nessus | Ubuntu Local Security Checks | high |
135280 | Slackware 14.2 / current : mozilla-firefox (SSA:2020-098-01) | Nessus | Slackware Local Security Checks | high |
135276 | Mozilla Firefox < 75.0 (mfsa2020-12) | Nessus | Windows | high |
135275 | Mozilla Firefox < 75.0 Multiple Vulnerabilities (mfsa2020-12) | Nessus | MacOS X Local Security Checks | high |
135274 | Mozilla Firefox ESR < 68.7 Multiple Vulnerabilities (mfsa2020-13) | Nessus | Windows | high |
135273 | Mozilla Firefox ESR < 68.7 Multiple Vulnerabilities (mfsa2020-13) | Nessus | MacOS X Local Security Checks | high |