CVE-2020-15659: Critical severity Mozilla Firefox vulnerability
Last updated 25 August 2025
Other sources
Mozilla developers and community members Kevin Brosnan, Alexandru Michis, Natalia Csoregi, Jason Kratzer, Christian Holler, Simon Giesecke, Luke Wagner reported memory safety bugs present in Firefox 78. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code.
— Mozilla
Mozilla developers and community members Natalia Csoregi, Simon Giesecke, Jason Kratzer, Christian Holler, and Luke Wagner reported memory safety bugs present in Firefox 78 and Firefox ESR 78.0. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code.
— Mozilla
Mozilla developers and community members reported memory safety bugs present in Firefox 78 and Firefox ESR 78.0. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 79, Firefox ESR < 68.11, Firefox ESR < 78.1, Thunderbird < 68.11, and Thunderbird < 78.1.
— Launchpad
Mozilla developers Jason Kratzer and Luke Wagner reported memory safety bugs present in Firefox 78 and Firefox ESR 68.10. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code.
Mozilla developers Jason Kratzer and Luke Wagner reported memory safety bugs present in Thunderbird 68.10. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code.
— Mozilla
Affected Software
Remediation
Patch Available
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is CVE-2020-15659?
CVE-2020-15659 is a vulnerability in Thunderbird, Firefox, and Firefox ESR that allows for memory corruption.
How can this vulnerability be exploited?
This vulnerability can be exploited by a remote attacker triggering memory corruption, potentially leading to arbitrary code execution.
Which versions of Thunderbird are affected?
Thunderbird versions up to 78.1 and 68.11 are affected by CVE-2020-15659.
Which versions of Firefox are affected?
Firefox versions up to 79 and Firefox ESR versions up to 68.11 are affected by CVE-2020-15659.
How can I fix CVE-2020-15659?
To fix CVE-2020-15659, it is recommended to update Thunderbird to version 78.2, Firefox to version 80, and Firefox ESR to version 68.12.