CVE-2019-11758
HIGHFirefox < 69.0, Firefox ESR < 68.2, Thunderbird < 68.2 - Out-of-bounds Write in Accessibility Engine
Title source: llmDescription
Mozilla community member Philipp reported a memory safety bug present in Firefox 68 when 360 Total Security was installed. This bug showed evidence of memory corruption in the accessibility engine and we presume that with enough effort that it could be exploited to run arbitrary code. This vulnerability affects Firefox < 69, Thunderbird < 68.2, and Firefox ESR < 68.2.
References (5)
Core 5
Core References
Vendor Advisory x_refsource_confirm
https://www.mozilla.org/security/advisories/mfsa2019-25/
Vendor Advisory x_refsource_confirm
https://www.mozilla.org/security/advisories/mfsa2019-35/
Vendor Advisory x_refsource_confirm
https://www.mozilla.org/security/advisories/mfsa2019-33/
Exploit, Issue Tracking, Vendor Advisory x_refsource_confirm
https://bugzilla.mozilla.org/show_bug.cgi?id=1536227
Third Party Advisory vendor-advisory
x_refsource_ubuntu
https://usn.ubuntu.com/4335-1/
Scores
CVSS v3
8.8
EPSS
0.0082
EPSS Percentile
74.6%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Details
CWE
CWE-787
Status
published
Products (4)
canonical/ubuntu_linux
16.04
mozilla/firefox
< 69.0
mozilla/firefox_esr
< 68.2
mozilla/thunderbird
< 68.2
Published
Jan 08, 2020
Tracked Since
Feb 18, 2026