CVE-2019-11693

CRITICAL

Firefox < 67 and Firefox ESR < 60.7 - Out-of-bounds Write in WebGL bufferdata

Title source: llm
STIX 2.1

Description

The bufferdata function in WebGL is vulnerable to a buffer overflow with specific graphics drivers on Linux. This could result in malicious content freezing a tab or triggering a potentially exploitable crash. *Note: this issue only occurs on Linux. Other operating systems are unaffected.*. This vulnerability affects Thunderbird < 60.7, Firefox < 67, and Firefox ESR < 60.7.

References (4)

Core 4
Core References
Issue Tracking, Permissions Required, Vendor Advisory x_refsource_misc
https://bugzilla.mozilla.org/show_bug.cgi?id=1532525

Scores

CVSS v3 9.8
EPSS 0.0059
EPSS Percentile 69.3%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-787
Status published
Products (2)
mozilla/firefox < 60.7.0
mozilla/thunderbird < 60.7.0
Published Jul 23, 2019
Tracked Since Feb 18, 2026