CVE-2020-12387: Use After Free
A race condition when running shutdown code for Web Worker led to a use-after-free vulnerability. This resulted in a potentially exploitable crash.
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2020-12387?
CVE-2020-12387 is classified as a medium severity vulnerability that can lead to a potential crash.
How do I fix CVE-2020-12387?
To fix CVE-2020-12387, upgrade to the latest versions of Firefox, Firefox ESR, or Thunderbird that contain the remediation.
Which versions are affected by CVE-2020-12387?
CVE-2020-12387 affects Mozilla Firefox versions up to 76, Firefox ESR up to 68.8, and Thunderbird versions up to 68.8.
What type of vulnerability is CVE-2020-12387?
CVE-2020-12387 is a use-after-free vulnerability caused by a race condition during the shutdown of Web Workers.
Can CVE-2020-12387 be exploited remotely?
CVE-2020-12387 may lead to a crash, which could potentially be exploited by an attacker under certain conditions.