Mozilla developers reported memory safety bugs present in Firefox 70. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 71.
CVSS Details
- CVSS 3.1 Base Score: 8.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | Jan 8, 2020 |
| Mfsa2019 36 | — | Upgrade to Mozilla Firefox version 71.0 | Dec 4, 2019 | Dec 3, 2019 |
| Oracle Solaris | — | Upgrade mail/thunderbird/plugin/thunderbird-lightning to version 68.12.0-11.4.27.0.1.82.0 on Solaris 11.4Upgrade web/data/firefox-bookmarks to version 78.3.0-11.4.27.0.1.82.0 on Solaris 11.4Upgrade mail/thunderbird to version 78.3.0-11.4.27.0.1.82.0 on Solaris 11.4Upgrade web/browser/firefox to version 78.3.0-11.4.27.0.1.82.0 on Solaris 11.4 | Jan 19, 2021 | Jan 8, 2020 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Jan 8, 2020 |
| Ubuntu | — | Upgrade firefox | Dec 10, 2019 | Dec 9, 2019 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub