CVE-2020-15669: Mozilla Firefox ESR
High severity, CVSS 8.8. EPSS: 1.1% chance of exploitation in the next 30 days.
When aborting an operation, such as a fetch, an abort signal may be deleted while alerting the objects to be notified. This results in a use-after-free and we presume that with enough effort it could have been exploited to run arbitrary code. This vulnerability affects Firefox ESR < 68.12 and Thunderbird < 68.12.
Affected products
- Mozilla Firefox ESR: before 68.12 (fixed in 68.12)
- Mozilla Thunderbird: before 68.12 (fixed in 68.12)
Published 2020-10-01. Last modified 2026-06-17.