{"api_version":"1","generated_at":"2026-07-23T14:09:47+00:00","cve":"CVE-2020-15671","urls":{"html":"https://cve.report/CVE-2020-15671","api":"https://cve.report/api/cve/CVE-2020-15671.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2020-15671","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2020-15671"},"summary":{"title":"CVE-2020-15671","description":"When typing in a password under certain conditions, a race may have occured where the InputContext was not being correctly set for the input field, resulting in the typed password being saved to the keyboard dictionary. This vulnerability affects Firefox for Android < 80.","state":"PUBLIC","assigner":"security@mozilla.org","published_at":"2020-10-01 19:15:00","updated_at":"2021-07-21 11:39:00"},"problem_types":["CWE-200","CWE-362"],"metrics":[],"references":[{"url":"https://bugzilla.mozilla.org/show_bug.cgi?id=1653862","name":"https://bugzilla.mozilla.org/show_bug.cgi?id=1653862","refsource":"MISC","tags":["Issue Tracking","Permissions Required","Vendor Advisory"],"title":"Access Denied","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.mozilla.org/security/advisories/mfsa2020-39/","name":"https://www.mozilla.org/security/advisories/mfsa2020-39/","refsource":"MISC","tags":["Release Notes","Vendor Advisory"],"title":"Security Vulnerabilities fixed in Firefox for Android 80 — Mozilla","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2020-15671","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2020-15671","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2020","cve_id":"15671","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"mozilla","cpe5":"firefox","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"android","cpe12":"*","cpe13":"*"},{"cve_year":"2020","cve_id":"15671","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"mozilla","cpe5":"firefox","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"android","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"data_type":"CVE","data_format":"MITRE","data_version":"4.0","CVE_data_meta":{"ID":"CVE-2020-15671","ASSIGNER":"security@mozilla.org","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"vendor_name":"Mozilla","product":{"product_data":[{"product_name":"Firefox for Android","version":{"version_data":[{"version_value":"80","version_affected":"<"}]}}]}}]}},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"Passwords could be saved to phone keyboard dictionary"}]}]},"references":{"reference_data":[{"url":"https://www.mozilla.org/security/advisories/mfsa2020-39/","refsource":"MISC","name":"https://www.mozilla.org/security/advisories/mfsa2020-39/"},{"url":"https://bugzilla.mozilla.org/show_bug.cgi?id=1653862","refsource":"MISC","name":"https://bugzilla.mozilla.org/show_bug.cgi?id=1653862"}]},"description":{"description_data":[{"lang":"eng","value":"When typing in a password under certain conditions, a race may have occured where the InputContext was not being correctly set for the input field, resulting in the typed password being saved to the keyboard dictionary. This vulnerability affects Firefox for Android < 80."}]}},"nvd":{"publishedDate":"2020-10-01 19:15:00","lastModifiedDate":"2021-07-21 11:39:00","problem_types":["CWE-200","CWE-362"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":3.1,"baseSeverity":"LOW"},"exploitabilityScore":1.6,"impactScore":1.4},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:H/Au:N/C:P/I:N/A:N","accessVector":"NETWORK","accessComplexity":"HIGH","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":2.6},"severity":"LOW","exploitabilityScore":4.9,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:mozilla:firefox:*:*:*:*:*:android:*:*","versionEndExcluding":"80.0","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2020","CveId":"15671","Ordinal":"177069","Title":"CVE-2020-15671","CVE":"CVE-2020-15671","Year":"2020"},"notes":[{"CveYear":"2020","CveId":"15671","Ordinal":"1","NoteData":"When typing in a password under certain conditions, a race may have occured where the InputContext was not being correctly set for the input field, resulting in the typed password being saved to the keyboard dictionary. This vulnerability affects Firefox for Android < 80.","Type":"Description","Title":null},{"CveYear":"2020","CveId":"15671","Ordinal":"2","NoteData":"2020-10-01","Type":"Other","Title":"Published"},{"CveYear":"2020","CveId":"15671","Ordinal":"3","NoteData":"2020-10-01","Type":"Other","Title":"Modified"}]}}}