EUVD-2020-27963
Under certain conditions, when running the nsDocShell destructor, a race condition can cause a use-after-free. We are aware of targeted attacks in the wild abusing this flaw. This vulnerability affects Thunderbird < 68.7.0, Firefox < 74.0.1, and Firefox ESR < 68.6.1.
- EUVD state
- Present in the current official mapping
- Known exploitation
- Recorded by ENISA since 3 Nov 2021. Evidence sources: cisa_kev.
- ENISA score
- 8.1 · CVSS 3.1
- Advisory evidence
- 17 linked advisory records
Only statements that explicitly mention a fix, patch, update, workaround or mitigation are shown here.
- csaf_opensuse · openSUSE-SU-2020:0544-1Security update for MozillaThunderbird
- csaf_suse · SUSE-SU-2020:0929-1Security update for MozillaFirefox
- csaf_redhat · RHSA-2020:1339Red Hat Security Advisory: firefox security update
- csaf_opensuse · openSUSE-SU-2020:0520-1Security update for MozillaThunderbird
- csaf_opensuse · openSUSE-SU-2020:0461-1Security update for MozillaFirefox
- csaf_suse · SUSE-SU-2020:14337-1Security update for MozillaFirefox
- csaf_redhat · RHSA-2020:1489Red Hat Security Advisory: thunderbird security update
- csaf_suse · SUSE-SU-2020:0928-1Security update for MozillaFirefox
- csaf_suse · SUSE-SU-2020:1027-1Security update for MozillaThunderbird
- csaf_redhat · RHSA-2020:1488Red Hat Security Advisory: thunderbird security update
- csaf_redhat · RHSA-2020:1496Red Hat Security Advisory: thunderbird security update
- csaf_redhat · RHSA-2020:1341Red Hat Security Advisory: firefox security update
- csaf_redhat · RHSA-2020:1340Red Hat Security Advisory: firefox security update
- csaf_redhat · RHSA-2020:1338Red Hat Security Advisory: firefox security update
- csaf_redhat · RHSA-2020:1495Red Hat Security Advisory: thunderbird security update
