CVE-2020-12407: Medium severity firefox vulnerability
Published Jun 2, 2020
·Updated
Last updated 24 July 2024
Other sources
Mozilla Developer Nicolas Silva found that when using WebRender, Firefox would under certain conditions leak arbitrary GPU memory to the visible screen. The leaked memory content was visible to the user, but not observable from web content.
Affected Software
3 affected componentsFixes available
Mozilla Firefox<77
77
Mozilla Firefox<77.0
debian/firefox
137.0.1-1
Event History
Jun 2, 2020
CVE Published
12:00 AM
Jul 9, 2020
CVE Published
via MITRE·02:54 PM
Data Sourced
via MITRE·02:54 PM
DescriptionWeakness
Jan 11, 2024
Data Sourced
via Launchpad·11:38 PM
Description
Sep 16, 2024
Data Sourced
via Ubuntu·02:21 AM
RemedyDescriptionSeverityAffected Software
Mar 27, 2025
Data Sourced
via Debian·03:31 AM
DescriptionAffected Software
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
1
What is the vulnerability ID of this issue?
The vulnerability ID is CVE-2020-12407.
2
Which software is affected by this vulnerability?
Firefox versions up to exclusive 77 are affected.
3
What is the severity level of CVE-2020-12407?
The severity level of CVE-2020-12407 is medium with a CVSS score of 6.5.
4
How can I fix the vulnerability in Firefox?
To fix the vulnerability in Firefox, update to version 77.0.1 or newer.
5
Where can I find more information about CVE-2020-12407?
More information about CVE-2020-12407 can be found in the Mozilla Security Advisory MFSA2020-20.