CISA Known Exploited Vulnerability

CVE-2020-6820

Mozilla · Firefox and Thunderbird

Mozilla Firefox And Thunderbird Use-After-Free Vulnerability

Date added
BOD 22-01 due date
CWE CWE-362
Ransomware Unknown

CISA description

Mozilla Firefox and Thunderbird contain a race condition vulnerability when handling a ReadableStream under certain conditions. The race condition creates a use-after-free vulnerability, causing unspecified impacts.

Required action

Apply updates per vendor instructions.