Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2020-6820

Опубликовано: 24 апр. 2020
Источник: debian
EPSS Низкий

Описание

Under certain conditions, when handling a ReadableStream, a race condition can cause a use-after-free. We are aware of targeted attacks in the wild abusing this flaw. This vulnerability affects Thunderbird < 68.7.0, Firefox < 74.0.1, and Firefox ESR < 68.6.1.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
firefoxfixed74.0.1-1package
firefox-esrfixed68.6.1esr-1package
thunderbirdfixed1:68.7.0-1package

Примечания

  • https://www.mozilla.org/en-US/security/advisories/mfsa2020-11/#CVE-2020-6820

  • https://www.mozilla.org/en-US/security/advisories/mfsa2020-14/#CVE-2020-6820

EPSS

Процентиль: 89%
0.04997
Низкий

Связанные уязвимости

CVSS3: 8.1
ubuntu
почти 6 лет назад

Under certain conditions, when handling a ReadableStream, a race condition can cause a use-after-free. We are aware of targeted attacks in the wild abusing this flaw. This vulnerability affects Thunderbird < 68.7.0, Firefox < 74.0.1, and Firefox ESR < 68.6.1.

CVSS3: 8.8
redhat
почти 6 лет назад

Under certain conditions, when handling a ReadableStream, a race condition can cause a use-after-free. We are aware of targeted attacks in the wild abusing this flaw. This vulnerability affects Thunderbird < 68.7.0, Firefox < 74.0.1, and Firefox ESR < 68.6.1.

CVSS3: 8.1
nvd
почти 6 лет назад

Under certain conditions, when handling a ReadableStream, a race condition can cause a use-after-free. We are aware of targeted attacks in the wild abusing this flaw. This vulnerability affects Thunderbird < 68.7.0, Firefox < 74.0.1, and Firefox ESR < 68.6.1.

CVSS3: 8.1
github
больше 3 лет назад

Under certain conditions, when handling a ReadableStream, a race condition can cause a use-after-free. We are aware of targeted attacks in the wild abusing this flaw. This vulnerability affects Thunderbird < 68.7.0, Firefox < 74.0.1, and Firefox ESR < 68.6.1.

CVSS3: 6.3
fstec
почти 6 лет назад

Уязвимость компонента ReadableStream веб-браузеров Firefox ESR и Firefox и почтового клиента Thunderbird, связанная с повторном освобождении области памяти, позволяющая нарушителю получить доступ к конфиденциальным данным, нарушить их целостность, а также вызвать отказ в обслуживании

EPSS

Процентиль: 89%
0.04997
Низкий