CVE-2020-12406: High severity Mozilla Firefox vulnerability
Last updated 25 August 2025
Other sources
Mozilla developer Iain Ireland discovered a missing type check during unboxed objects removal, resulting in a crash. We presume that with enough effort that it could be exploited to run arbitrary code.
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is CVE-2020-12406?
CVE-2020-12406 is a vulnerability discovered in Mozilla Thunderbird, Firefox, and Firefox ESR that could lead to a crash or potentially allow an attacker to run arbitrary code.
Which software versions are affected by CVE-2020-12406?
CVE-2020-12406 affects Mozilla Thunderbird version up to 68.9, Firefox version up to 77, and Firefox ESR version up to 68.9.
What is the severity of CVE-2020-12406?
CVE-2020-12406 has a severity level of high (severity value: 7).
How can CVE-2020-12406 be exploited?
With enough effort, CVE-2020-12406 could be exploited to run arbitrary code.
How can I fix CVE-2020-12406?
To fix CVE-2020-12406, update Mozilla Thunderbird to version 68.9 or newer, Firefox to version 77 or newer, or Firefox ESR to version 68.9 or newer.