When recursing through graphical layers while scrolling, an iterator may have become invalid, resulting in a potential use-after-free. This occurs because the function APZCTreeManager::ComputeClippedCompositionBounds did not follow iterator invalidation rules. This vulnerability affects Firefox < 81, Thunderbird < 78.3, and Firefox ESR < 78.3.
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-15678.json"
[
{
"events": [
{
"introduced": "0"
},
{
"fixed": "81.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"fixed": "78.3"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"fixed": "78.3"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "15.1"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "15.2"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "9.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "10.0"
}
]
}
]