CVE Feed

    Dashboard / CVE / CVE-2020-15666

    CVE-2020-15666

    When trying to load a non-video in an audio/video context the exact status code (200, 302, 404, 500, 412, 403, etc.) was disclosed via the MediaError Message. This level of information leakage is inconsistent with the standardized onerror/onsuccess disclosure and can lead to inferring login status to services or device discovery on a local network among other attacks. This vulnerability affects Firefox < 80 and Firefox for Android < 80.

    Published:Oct 1, 2020
    Last Modified:Aug 19, 2026
    EPS:Oct 1, 2020
    EPSS Score:0.01234
    CVSS Score:6.5

    Affected Products

    Vendor
    Mozilla
    Product
    Firefox
    Vendor
    Mozilla
    Product
    Firefox Mobile

    Related CVEs

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High