CISA Known Exploited Vulnerability

CVE-2020-6819

Mozilla · Firefox and Thunderbird

Mozilla Firefox And Thunderbird Use-After-Free Vulnerability

Date added
BOD 22-01 due date
CWE CWE-362, CWE-416
Ransomware Unknown

CISA description

Mozilla Firefox and Thunderbird contain a race condition vulnerability when running the nsDocShell destructor under certain conditions. The race condition creates a use-after-free vulnerability, causing unspecified impacts.

Required action

Apply updates per vendor instructions.