CVE-2020-15680: Mozilla Firefox

Medium severity, CVSS 5.3. EPSS: 0.9% chance of exploitation in the next 30 days.

If a valid external protocol handler was referenced in an image tag, the resulting broken image size could be distinguished from a broken image size of a non-existent protocol handler. This allowed an attacker to successfully probe whether an external protocol handler was registered. This vulnerability affects Firefox < 82.

Affected products

  • Mozilla Firefox: before 82.0 (fixed in 82.0)

Published 2020-10-22. Last modified 2026-06-17.