CVE-2020-26963: Medium severity firefox vulnerability
Published Nov 17, 2020
·Updated
Repeated calls to the history and location interfaces could have been used to hang the browser. This was addressed by introducing rate-limiting to these API calls.
Affected Software
2 affected componentsFixes available
Mozilla Firefox<83
83
Mozilla Firefox<83.0
Event History
Nov 17, 2020
CVE Published
12:00 AM
Dec 9, 2020
CVE Published
via MITRE·12:24 AM
Data Sourced
via MITRE·12:24 AM
DescriptionWeakness
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
1
What is the vulnerability ID for this security issue?
The vulnerability ID for this security issue is CVE-2020-26963.
2
What is the title of this vulnerability?
The title of this vulnerability is 'Repeated calls to the history and location interfaces could have been used to hang the browser.'
3
Which browser is affected by this vulnerability?
This vulnerability affects Mozilla Firefox version up to, but not including, 83.0.
4
How was this vulnerability addressed?
This vulnerability was addressed by introducing rate-limiting to the history and location API calls.
5
What is the severity level of this vulnerability?
The severity level of this vulnerability is medium, with a CVSS score of 4.3.