CVE-2019-11691
A use-after-free vulnerability can occur when working with XMLHttpRequest (XHR) in an event loop, causing the XHR main thread to be called after it has been freed.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.61%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
A use-after-free vulnerability can occur when working with XMLHttpRequest (XHR) in an event loop, causing the XHR main thread to be called after it has been freed. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 60.7, Firefox < 67, and Firefox ESR < 60.7.
- CVSS 3.0
- 9.8 CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 1.61% probability · 74th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-416
- Affected
- mozilla/firefox · mozilla/firefox esr · mozilla/thunderbird
- Source
- security@mozilla.org
References
- https://bugzilla.mozilla.org/show_bug.cgi?id=1542465Issue Tracking, Permissions Required, Vendor Advisory
- https://www.mozilla.org/security/advisories/mfsa2019-13/Vendor Advisory
- https://www.mozilla.org/security/advisories/mfsa2019-14/Vendor Advisory
- https://www.mozilla.org/security/advisories/mfsa2019-15/Vendor Advisory
- https://bugzilla.mozilla.org/show_bug.cgi?id=1542465Issue Tracking, Permissions Required, Vendor Advisory
- https://www.mozilla.org/security/advisories/mfsa2019-13/Vendor Advisory
- https://www.mozilla.org/security/advisories/mfsa2019-14/Vendor Advisory
- https://www.mozilla.org/security/advisories/mfsa2019-15/Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.