CVE-2019-11758

HIGH

Firefox < 69.0, Firefox ESR < 68.2, Thunderbird < 68.2 - Out-of-bounds Write in Accessibility Engine

Title source: llm
STIX 2.1

Description

Mozilla community member Philipp reported a memory safety bug present in Firefox 68 when 360 Total Security was installed. This bug showed evidence of memory corruption in the accessibility engine and we presume that with enough effort that it could be exploited to run arbitrary code. This vulnerability affects Firefox < 69, Thunderbird < 68.2, and Firefox ESR < 68.2.

References (5)

Core 5
Core References
Vendor Advisory x_refsource_confirm
https://www.mozilla.org/security/advisories/mfsa2019-25/
Vendor Advisory x_refsource_confirm
https://www.mozilla.org/security/advisories/mfsa2019-35/
Vendor Advisory x_refsource_confirm
https://www.mozilla.org/security/advisories/mfsa2019-33/
Exploit, Issue Tracking, Vendor Advisory x_refsource_confirm
https://bugzilla.mozilla.org/show_bug.cgi?id=1536227
Third Party Advisory vendor-advisory x_refsource_ubuntu
https://usn.ubuntu.com/4335-1/

Scores

CVSS v3 8.8
EPSS 0.0082
EPSS Percentile 74.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Details

CWE
CWE-787
Status published
Products (4)
canonical/ubuntu_linux 16.04
mozilla/firefox < 69.0
mozilla/firefox_esr < 68.2
mozilla/thunderbird < 68.2
Published Jan 08, 2020
Tracked Since Feb 18, 2026