Back

HIGH

Mozilla: Memory safety bugs fixed in Firefox 73 and Firefox ESR 68.5

Published Mar 2, 2020

Description

Mozilla developers and community members reported memory safety bugs present in Firefox 72 and Firefox ESR 68.4. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. In general, these flaws cannot be exploited through email in the Thunderbird product because scripting is disabled when reading mail, but are potentially risks in browser or browser-like contexts. This vulnerability affects Thunderbird < 68.5, Firefox < 73, and Firefox < ESR68.5.

Affected products

Remediation

No remediation recorded yet.

References (15)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mozilla
Published Mar 2, 2020
Updated Aug 4, 2024
Reserved Jan 10, 2020
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Important
Public date Feb 11, 2020
ENISA EUVD
Assigner mozilla
Published Mar 2, 2020
Updated Aug 4, 2024
Exploited since n/a
EUVD-2020-27947