CVE-2020-26974: Use After Free
When flex-basis was used on a table wrapper, a StyleGenericFlexBasis object could have been incorrectly cast to the wrong type. This resulted in a heap user-after-free, memory corruption, and a potentially exploitable crash.
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2020-26974?
CVE-2020-26974 is considered a critical vulnerability due to its potential for memory corruption and exploitable crashes.
How do I fix CVE-2020-26974?
To mitigate CVE-2020-26974, users should update Mozilla Firefox, Firefox ESR, or Thunderbird to versions 84 and 78.6 or later.
What types of software are affected by CVE-2020-26974?
CVE-2020-26974 affects Mozilla Firefox, Firefox ESR, and Thunderbird versions below specified thresholds.
Can CVE-2020-26974 lead to remote code execution?
While CVE-2020-26974 may cause a crash, it has not been confirmed to directly lead to remote code execution.
Is CVE-2020-26974 exploitable by attackers?
Yes, CVE-2020-26974 could potentially be exploited by attackers to cause crashes and disrupt service.