CVE-2020-26950
In certain circumstances, the MCallGetProperty opcode can be emitted with unmet assumptions resulting in an exploitable use-after-free condition. This vulnerability affects Firefox < 82.0.3, Firefox ESR < 78.4.1, and Thunderbird < 78.4.2.
- Affected products
- Alt Linux, Centos, Firefox, Firefox Esr, Linuxmint, Red Hat, Suse, Thunderbird
- Mozilla Firefox
- < 82.0.3
- Mozilla Firefox Esr
- < 78.4.1
- Mozilla Thunderbird
- < 78.4.2
- Fix
- Available
- CVSS 2.0
- 9.3 HIGH
- CVSS 3.1
- 8.8 HIGH
- EPSS
- 42.3% (99th percentile)
- Weakness
- CWE-416
- NVD status
- Modified
- Published
- 2020-12-09
CVE-2020-26950 at NVD
3 known exploits for CVE-2020-26950
Proof-of-concept code and exploit modules indexed by Sploitus