SecPod

Learn Search

Search across all Learn content

← Back to Security Research
Security Update: Mozilla Fixes Actively Exploited Zero-Days in Firefox

Security Update: Mozilla Fixes Actively Exploited Zero-Days in Firefox

Mozilla fixed two critical zero-days in its popular web browser, Firefox. Using a vulnerability management tool. Mozilla is aware of active exploitation of these vulnerabilities. There is no specific information about the threat groups or malwares utilizing these vulnerabilities. These are the Firef...

Apr 5, 2020By Vidita V Koushik2 min read

Mozilla fixed two critical zero-days in its popular web browser, Firefox. Using a vulnerability management tool. Mozilla is aware of active exploitation of these vulnerabilities. There is no specific information about the threat groups or malwares utilizing these vulnerabilities. These are the Firefox vulnerabilities.

Firefox vulnerabilities Zero-Days

As per the advisory,

  • CVE-2020-6819 is a use-after-free vulnerability when running the nsDocShell destructor due to a  race condition.
  • CVE-2020-6820 is a use-after-free vulnerability when handling a ReadableStream due to a race condition.

Both the zero-days are use-after-free issues in different components. A use-after-free(CWE-416) issue is one where a memory is referenced after it is freed. However, vulnerabilities of this type can be used to corrupt memory and launch denial of service or remote code execution attacks. Depending on the privileges of the targeted user, an attacker can install programs; view, change, or delete data; or create new accounts with full user rights. A patch management tool can patch such vulnerabilities.

Affected products in Firefox vulnerabilities

  • Firefox versions prior to 74.0.1
  • Firefox ESR versions 68.6.1

Impact

Attackers can either abuse these vulnerabilities to crash the application or execute arbitrary code in the context of the browser.

Solution

Please refer to this KB article to apply the patches using SanerNow.

Featured Posts

Open Top Vulnerability Scanning Tools 2024

Top Vulnerability Scanning Tools 2024

CVE Research

Top Vulnerability Scanning Tools 2024

According to statistics, a new cyberattack was detected every 39 seconds in 2023! With this rise in number of attacks, protecting sensitive data becomes crucial and challenging. To protect IT, vulnerability scanners are the lead at defense, actively identifying weaknesses within systems and networks

Sep 17, 2026

Open The Webm Zero-Days: All Over The Wild

The Webm Zero-Days: All Over The Wild

CVE Research

The Webm Zero-Days: All Over The Wild

Webmproject, a popular media file format, has been experiencing hardships in security. Two of its libraries, libwebp and libvpx, have been found to contain zero-day vulnerabilities that affect multiple commonly used software products, such as Chrome, Edge, Tor, Telegram, and more! The two notorious

Sep 17, 2026

Open The Ultimate Vulnerability Assessment Checklist

The Ultimate Vulnerability Assessment Checklist

CVE Research

The Ultimate Vulnerability Assessment Checklist

Vulnerability assessment is the process of identifying and assessing vulnerabilities. It makes up for a significant chunk of vulnerability management, and vulnerability management relies heavily on it. Without properly assessing vulnerabilities, your vulnerability management program might fail to me

Sep 17, 2026

Open SCAP Feed Release : 02-Dec-2017

SCAP Feed Release : 02-Dec-2017

CVE Research

SCAP Feed Release : 02-Dec-2017

The following SCAP content has been released to SCAP Repo and SecPod Saner Solution. SecPod Saner will automatically pull the relevant content on its next scheduled update. oval:org.secpod.oval:def:42845 CVE-2017-11293 Out-of-bounds read vulnerability in Adobe Acrobat and Reader products via unspeci

Sep 17, 2026