Related Vulnerabilities: CVE-2020-26974  

A security issue was found in Firefox before 84.0. When flex-basis was used on a table wrapper, a StyleGenericFlexBasis object could have been incorrectly cast to the wrong type. This resulted in a heap user-after-free, memory corruption, and a potentially exploitable crash.

Severity High

Remote Yes

Type Arbitrary code execution

Description

A security issue was found in Firefox before 84.0. When flex-basis was used on a table wrapper, a StyleGenericFlexBasis object could have been incorrectly cast to the wrong type. This resulted in a heap user-after-free, memory corruption, and a potentially exploitable crash.

AVG-1362 firefox 83.0-2 84.0-1 High Fixed

https://www.mozilla.org/en-US/security/advisories/mfsa2020-54/#CVE-2020-26974
https://bugzilla.mozilla.org/show_bug.cgi?id=1681022