
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2020-15674 is a high-severity memory safety vulnerability discovered in Firefox 80. The vulnerability was reported by Mozilla developers Byron Campen and Christian Holler and was fixed with the release of Firefox 81 in September 2020 (Mozilla Advisory).
The vulnerability is classified as a memory safety bug with a CVSS 3.1 base score of 8.8 (High). The vulnerability requires network access, has low attack complexity, requires no privileges, but does need user interaction. The scope is unchanged, with high impact potential on confidentiality, integrity, and availability (Ubuntu CVE).
The vulnerability showed evidence of memory corruption and could potentially be exploited to run arbitrary code on affected systems. This type of flaw could allow attackers to execute malicious code if a user was tricked into visiting a specially crafted website (Threatpost).
The vulnerability affects Firefox version 80 and requires user interaction to exploit. While the bug showed evidence of memory corruption, it would require significant effort to develop into a working exploit (Mozilla Advisory).
The vulnerability was fixed in Firefox 81. Users should update to Firefox 81 or later to receive the security patch. For Ubuntu systems, the fix was released in version 81.0+build2-0ubuntu0.20.04.1 for Ubuntu 20.04, version 81.0+build2-0ubuntu0.18.04.1 for Ubuntu 18.04, and version 81.0+build2-0ubuntu0.16.04.1 for Ubuntu 16.04 (Ubuntu Notice).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."