9.8
CVSSv3

CVE-2020-26972

Published: 07/01/2021 Updated: 11/01/2021
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

A security issue was found in Firefox prior to 84.0. The lifecycle of IPC Actors allows managed actors to outlive their manager actors; and the former must ensure that they are not attempting to use a dead actor they have a reference to. Such a check was omitted in WebGL, resulting in a use-after-free and a potentially exploitable crash.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

mozilla firefox

Vendor Advisories

Mozilla Foundation Security Advisory 2020-54 Security Vulnerabilities fixed in Firefox 84 Announced December 15, 2020 Impact critical Products Firefox Fixed in Firefox 84 ...
A security issue was found in Firefox before 840 The lifecycle of IPC Actors allows managed actors to outlive their manager actors; and the former must ensure that they are not attempting to use a dead actor they have a reference to Such a check was omitted in WebGL, resulting in a use-after-free and a potentially exploitable crash ...