Sploitus

CVE-2020-6806

No indexed exploits for CVE-2020-6806 yet

By carefully crafting promise resolutions, it was possible to cause an out-of-bounds read off the end of an array resized during script execution. This could have led to memory corruption and a potentially exploitable crash. This vulnerability affects Thunderbird < 68.6, Firefox < 74, Firefox < ESR68.6, and Firefox ESR < 68.6.

Mozilla Firefox
< 74.0
Mozilla Firefox Esr
< 68.6.0
Mozilla Thunderbird
< 68.6.0
Fix
Available
CVSS 3.1
8.8 HIGH
EPSS
2.5% (83th percentile)
Weakness
CWE-125
NVD status
Modified
Published
2020-03-25
CVE-2020-6806 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2020-6806 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2020-6806 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.