CVE-2020-12422: Mozilla Firefox

High severity, CVSS 8.8. EPSS: 1.9% chance of exploitation in the next 30 days.

In non-standard configurations, a JPEG image created by JavaScript could have caused an internal variable to overflow, resulting in an out of bounds write, memory corruption, and a potentially exploitable crash. This vulnerability affects Firefox < 78.

Affected products

  • Mozilla Firefox: before 78.0 (fixed in 78.0)
  • Opensuse Leap: version 15.1 only; version 15.2 only

Published 2020-07-09. Last modified 2026-06-17.