CVE-2020-12395
NixOS vulnerability analysis and mitigation

Overview

Mozilla developers and community members reported memory safety bugs present in Firefox 75 and Firefox ESR 68.7. The vulnerability (CVE-2020-12395) was discovered in May 2020 and affects Firefox ESR < 68.8, Firefox < 76, and Thunderbird < 68.8.0. These memory safety bugs showed evidence of memory corruption that could potentially be exploited to run arbitrary code (Mozilla Advisory).

Technical details

The vulnerability is classified as a critical severity issue with a CVSS v3.1 base score of 9.8 (CRITICAL) and vector string CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. The issue is categorized as an Out-of-bounds Write (CWE-787) vulnerability. The bugs were discovered by multiple Mozilla developers and community members including Alexandru Michis, Jason Kratzer, philipp, Ted Campbell, Bas Schouten, André Bargull, and Karl Tomlinson (NVD).

Impact

The vulnerability could allow an attacker to execute arbitrary code with enough effort due to memory corruption issues. This could potentially lead to complete system compromise with the privileges of the affected application (Mozilla Advisory, Gentoo Advisory).

Exploitability

The memory safety bugs showed evidence of memory corruption, and Mozilla security researchers presumed that with sufficient effort, these vulnerabilities could be exploited to execute arbitrary code. The vulnerability requires network access but no authentication or user interaction (NVD).

Mitigation and workarounds

The vulnerability was fixed in Firefox 76.0, Firefox ESR 68.8.0, and Thunderbird 68.8.0. Users are advised to upgrade to these versions or later to mitigate the vulnerability. For Thunderbird specifically, while these flaws cannot generally be exploited through email since scripting is disabled when reading mail, they remain potential risks in browser or browser-like contexts (Mozilla Advisory).

Additional resources


SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-86738CRITICAL9.3
  • NixOS logoNixOS
  • snipe-it
NoYesSep 08, 2026
CVE-2026-86734HIGH7.1
  • NixOS logoNixOS
  • snipe-it
NoYesSep 08, 2026
CVE-2026-86735MEDIUM5.9
  • NixOS logoNixOS
  • snipe-it
NoYesSep 08, 2026
CVE-2026-86737MEDIUM5.3
  • NixOS logoNixOS
  • snipe-it
NoYesSep 08, 2026
CVE-2026-86736MEDIUM5.3
  • NixOS logoNixOS
  • snipe-it
NoYesSep 08, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management