CVE-2020-15674
NixOS vulnerability analysis and mitigation

Overview

CVE-2020-15674 is a high-severity memory safety vulnerability discovered in Firefox 80. The vulnerability was reported by Mozilla developers Byron Campen and Christian Holler and was fixed with the release of Firefox 81 in September 2020 (Mozilla Advisory).

Technical details

The vulnerability is classified as a memory safety bug with a CVSS 3.1 base score of 8.8 (High). The vulnerability requires network access, has low attack complexity, requires no privileges, but does need user interaction. The scope is unchanged, with high impact potential on confidentiality, integrity, and availability (Ubuntu CVE).

Impact

The vulnerability showed evidence of memory corruption and could potentially be exploited to run arbitrary code on affected systems. This type of flaw could allow attackers to execute malicious code if a user was tricked into visiting a specially crafted website (Threatpost).

Exploitability

The vulnerability affects Firefox version 80 and requires user interaction to exploit. While the bug showed evidence of memory corruption, it would require significant effort to develop into a working exploit (Mozilla Advisory).

Mitigation and workarounds

The vulnerability was fixed in Firefox 81. Users should update to Firefox 81 or later to receive the security patch. For Ubuntu systems, the fix was released in version 81.0+build2-0ubuntu0.20.04.1 for Ubuntu 20.04, version 81.0+build2-0ubuntu0.18.04.1 for Ubuntu 18.04, and version 81.0+build2-0ubuntu0.16.04.1 for Ubuntu 16.04 (Ubuntu Notice).

Additional resources


SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-78662HIGH7.5
  • Docker logoDocker
  • telegraf-1.38
NoYesSep 02, 2026
CVE-2026-56855HIGH7.5
  • Docker logoDocker
  • flux-notification-controller
NoYesSep 02, 2026
CVE-2026-84642HIGH7.5
  • NixOS logoNixOS
  • cpe:2.3:a:mozilla:thunderbird
NoYesSep 01, 2026
CVE-2026-84641HIGH7.5
  • NixOS logoNixOS
  • thunderbird
NoYesSep 01, 2026
CVE-2026-84640HIGH7.5
  • NixOS logoNixOS
  • cpe:2.3:a:mozilla:thunderbird
NoYesSep 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management