Skip to content
COOEY

EXPOSURES › CVE-2020-6819

CVE-2020-6819

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2021-11-03 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2020-6819 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 75/100 exploited-in-wildunpatchedrce

Mozilla Firefox and Thunderbird suffered a use-after-free vulnerability that was actively exploited in the wild.

A race condition in Firefox and Thunderbird allowed attackers to execute arbitrary code via a use-after-free bug, which was later added to CISA's KEV catalog. DIB organizations must ensure their browsers are patched immediately, as unpatched versions can lead to remote code execution and compromise of sensitive data. This failure highlights the risk of relying on software with known, unpatched vulnerabilities that are actively exploited.

Shame score — The vulnerability was actively exploited in the wild and added to CISA's KEV catalog, indicating a significant security failure that could have led to data breaches or system compromises if not patched.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Mozilla Firefox and Thunderbird contain a race condition vulnerability when running the nsDocShell destructor under certain conditions. The race condition creates a use-after-free vulnerability, causing unspecified impacts.

SENTIMENT · TRUSTED SOURCES
synthesis neutral +0.00
No security press or authoritative commentary found in the provided sources; only CVE databases and unrelated news.
cooey ↗ neutral +0.00
Neutral CVE database entry with no commentary on Mozilla's handling.
"Mozilla Firefox and Thunderbird contain a race condition vulnerability when running the nsDocShell destructor under certain conditions. The race condition creates a use-after-free vulnerability, causing unspecified impacts."
recentbreaches.com ↗ neutral +0.00
Irrelevant breach tracker site with no coverage of CVE-2020-6819.
www.cvefind.com ↗ neutral +0.00
Irrelevant CVE database site with no commentary on Mozilla's handling.
xposedornot.com ↗ neutral +0.00
Irrelevant breach directory site with no coverage of CVE-2020-6819.
app.opencve.io ↗ neutral +0.00
Irrelevant CVE database site with no commentary on Mozilla's handling.
nypost.com ↗ neutral +0.00
Irrelevant news article about a child abuse case.
gizmodo.com ↗ neutral +0.00
Irrelevant news article about a crypto wallet breach.
AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.