CVE-2020-12387: Mozilla Firefox
High severity, CVSS 8.1. EPSS: 1.4% chance of exploitation in the next 30 days.
A race condition when running shutdown code for Web Worker led to a use-after-free vulnerability. This resulted in a potentially exploitable crash. This vulnerability affects Firefox ESR < 68.8, Firefox < 76, and Thunderbird < 68.8.0.
Affected products
- Mozilla Firefox: before 76.0 (fixed in 76.0)
- Mozilla Firefox ESR: before 68.8.0 (fixed in 68.8.0)
- Mozilla Thunderbird: before 68.8.0 (fixed in 68.8.0)
Published 2020-05-26. Last modified 2026-06-17.