CVE-2020-12418: Medium severity Mozilla Firefox vulnerability
Last updated 25 August 2025
Other sources
Manipulating individual parts of a URL object could have caused an out-of-bounds read, leaking process memory to malicious JavaScript.
— Mozilla
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is CVE-2020-12418?
CVE-2020-12418 is a vulnerability in Mozilla Firefox and Thunderbird that allows for manipulation of URL objects, resulting in an out-of-bounds read and potential memory leakage.
Which software versions are affected by CVE-2020-12418?
Mozilla Firefox versions up to 78, Firefox ESR versions up to 68.10, Thunderbird versions up to 68.10, and Thunderbird versions up to 78 are affected by CVE-2020-12418.
What is the severity of CVE-2020-12418?
The severity of CVE-2020-12418 is high with a severity value of 7.
How can CVE-2020-12418 be exploited?
CVE-2020-12418 can be exploited by manipulating individual parts of a URL object, which triggers an out-of-bounds read and potentially leaking process memory to malicious JavaScript.
How can CVE-2020-12418 be mitigated?
To mitigate CVE-2020-12418, users should update to the latest versions of Mozilla Firefox and Thunderbird, which include the necessary security patches.