CVE-2020-12410: High severity Mozilla Thunderbird vulnerability
Last updated 25 August 2025
Other sources
Mozilla developers reported memory safety bugs present in Firefox 76 and Firefox ESR 68.8. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Thunderbird < 68.9.0, Firefox < 77, and Firefox ESR < 68.9.
— Launchpad
Mozilla developers Tom Tung and Karl Tomlinson reported memory safety bugs present in Firefox 68.8. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code.
Mozilla developers Tom Tung and Karl Tomlinson reported memory safety bugs present in Firefox 76 and Firefox ESR 68.8. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code.
— Mozilla
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2020-12410?
The severity of CVE-2020-12410 is critical with a CVSS score of 8.8.
Which software versions are affected by CVE-2020-12410?
Firefox 76, Firefox ESR 68.8, and Thunderbird < 68.9.0 are affected by CVE-2020-12410.
How can CVE-2020-12410 be exploited?
CVE-2020-12410 can be exploited by running arbitrary code through the exploitation of memory corruption.
How do I fix CVE-2020-12410?
To fix CVE-2020-12410, update to Thunderbird 68.9.0 or later, Firefox 77.0.1 or later, or apply the necessary patches for the affected Ubuntu Linux versions.
Where can I find more information about CVE-2020-12410?
You can find more information about CVE-2020-12410 at the following references: [Bugzilla](https://bugzilla.mozilla.org/buglist.cgi?bug_id=1619305%2C1632717), [Ubuntu Security Notice](https://usn.ubuntu.com/4421-1/), [Mozilla Security Advisories](https://www.mozilla.org/security/advisories/mfsa2020-20/).