CVE-2019-11691

CRITICAL
New! CVE Severity Now Using CVSS v3

The calculated severity for CVEs has been updated to use CVSS v3 by default. CVEs that do not have a CVSS v3 score will fall back CVSS v2 for calculating severity. Severity display preferences can be toggled in the settings dropdown.

Description

A use-after-free vulnerability can occur when working with XMLHttpRequest (XHR) in an event loop, causing the XHR main thread to be called after it has been freed. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 60.7, Firefox < 67, and Firefox ESR < 60.7.

References

https://bugzilla.mozilla.org/show_bug.cgi?id=1542465

https://www.mozilla.org/security/advisories/mfsa2019-13/

https://www.mozilla.org/security/advisories/mfsa2019-14/

https://www.mozilla.org/security/advisories/mfsa2019-15/

Details

Source: MITRE

Published: 2019-07-23

Updated: 2019-07-26

Type: CWE-416

Risk Information

CVSS v2

Base Score: 7.5

Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Impact Score: 6.4

Exploitability Score: 10

Severity: HIGH

CVSS v3

Base Score: 9.8

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Impact Score: 5.9

Exploitability Score: 3.9

Severity: CRITICAL

Tenable Plugins

View all (53 total)

IDNameProductFamilySeverity
145688CentOS 8 : firefox (CESA-2019:1269)NessusCentOS Local Security Checks
critical
145630CentOS 8 : thunderbird (CESA-2019:1308)NessusCentOS Local Security Checks
critical
128698NewStart CGSL MAIN 4.06 : thunderbird Multiple Vulnerabilities (NS-SA-2019-0178)NessusNewStart CGSL Local Security Checks
critical
128691NewStart CGSL MAIN 4.06 : firefox Multiple Vulnerabilities (NS-SA-2019-0175)NessusNewStart CGSL Local Security Checks
critical
127589Oracle Linux 8 : thunderbird (ELSA-2019-1308)NessusOracle Linux Local Security Checks
critical
127587Oracle Linux 8 : firefox (ELSA-2019-1269)NessusOracle Linux Local Security Checks
critical
127459NewStart CGSL MAIN 4.05 : thunderbird Multiple Vulnerabilities (NS-SA-2019-0169)NessusNewStart CGSL Local Security Checks
critical
127455NewStart CGSL MAIN 4.05 : firefox Multiple Vulnerabilities (NS-SA-2019-0167)NessusNewStart CGSL Local Security Checks
critical
127439NewStart CGSL CORE 5.04 / MAIN 5.04 : firefox Multiple Vulnerabilities (NS-SA-2019-0159)NessusNewStart CGSL Local Security Checks
critical
127438NewStart CGSL CORE 5.04 / MAIN 5.04 : thunderbird Multiple Vulnerabilities (NS-SA-2019-0158)NessusNewStart CGSL Local Security Checks
critical
127305NewStart CGSL CORE 5.05 / MAIN 5.05 : thunderbird Multiple Vulnerabilities (NS-SA-2019-0088)NessusNewStart CGSL Local Security Checks
critical
127304NewStart CGSL CORE 5.05 / MAIN 5.05 : firefox Multiple Vulnerabilities (NS-SA-2019-0087)NessusNewStart CGSL Local Security Checks
critical
125948Ubuntu 16.04 LTS / 18.04 LTS / 18.10 / 19.04 : Firefox regression (USN-3991-3)NessusUbuntu Local Security Checks
critical
125901Amazon Linux 2 : thunderbird (ALAS-2019-1229)NessusAmazon Linux Local Security Checks
critical
125809openSUSE Security Update : MozillaFirefox (openSUSE-2019-1534)NessusSuSE Local Security Checks
critical
125803CentOS 6 : thunderbird (CESA-2019:1310)NessusCentOS Local Security Checks
critical
125802CentOS 7 : thunderbird (CESA-2019:1309)NessusCentOS Local Security Checks
critical
125766Ubuntu 16.04 LTS / 18.04 LTS / 18.10 / 19.04 : firefox regression (USN-3991-2)NessusUbuntu Local Security Checks
critical
125716Scientific Linux Security Update : thunderbird on SL7.x x86_64 (20190604)NessusScientific Linux Local Security Checks
critical
125715Scientific Linux Security Update : thunderbird on SL6.x i386/x86_64 (20190604)NessusScientific Linux Local Security Checks
critical
125702SUSE SLED15 / SLES15 Security Update : MozillaFirefox (SUSE-SU-2019:1405-1)NessusSuSE Local Security Checks
critical
125692RHEL 6 : thunderbird (RHSA-2019:1310)NessusRed Hat Local Security Checks
critical
125691RHEL 7 : thunderbird (RHSA-2019:1309)NessusRed Hat Local Security Checks
critical
125690RHEL 8 : thunderbird (RHSA-2019:1308)NessusRed Hat Local Security Checks
critical
125689Oracle Linux 6 : thunderbird (ELSA-2019-1310)NessusOracle Linux Local Security Checks
critical
125688Oracle Linux 7 : thunderbird (ELSA-2019-1309)NessusOracle Linux Local Security Checks
critical
125672SUSE SLED12 / SLES12 Security Update : MozillaFirefox (SUSE-SU-2019:1388-1)NessusSuSE Local Security Checks
critical
125669openSUSE Security Update : MozillaThunderbird (openSUSE-2019-1484)NessusSuSE Local Security Checks
critical
125554CentOS 6 : firefox (CESA-2019:1267)NessusCentOS Local Security Checks
critical
125553CentOS 7 : firefox (CESA-2019:1265)NessusCentOS Local Security Checks
critical
125545Ubuntu 16.04 LTS / 18.04 LTS / 18.10 / 19.04 : Thunderbird vulnerabilities (USN-3997-1)NessusUbuntu Local Security Checks
critical
125449Scientific Linux Security Update : firefox on SL7.x x86_64 (20190524)NessusScientific Linux Local Security Checks
critical
125447Scientific Linux Security Update : firefox on SL6.x i386/x86_64 (20190523)NessusScientific Linux Local Security Checks
critical
125444Oracle Linux 6 : firefox (ELSA-2019-1267)NessusOracle Linux Local Security Checks
critical
125443Oracle Linux 7 : firefox (ELSA-2019-1265)NessusOracle Linux Local Security Checks
critical
125415Debian DSA-4451-1 : thunderbird - security updateNessusDebian Local Security Checks
critical
125412Debian DLA-1806-1 : thunderbird security updateNessusDebian Local Security Checks
critical
125385RHEL 8 : firefox (RHSA-2019:1269)NessusRed Hat Local Security Checks
critical
125383RHEL 6 : firefox (RHSA-2019:1267)NessusRed Hat Local Security Checks
critical
125382RHEL 7 : firefox (RHSA-2019:1265)NessusRed Hat Local Security Checks
critical
125374Debian DLA-1800-1 : firefox-esr security updateNessusDebian Local Security Checks
critical
125363Mozilla Firefox ESR < 60.7NessusWindows
critical
125362Mozilla Firefox ESR < 60.7NessusMacOS X Local Security Checks
critical
125361Mozilla Firefox < 67.0NessusWindows
critical
125360Mozilla Firefox < 67.0NessusMacOS X Local Security Checks
critical
125359Mozilla Thunderbird < 60.7NessusWindows
critical
125358Mozilla Thunderbird < 60.7NessusMacOS X Local Security Checks
critical
125346FreeBSD : mozilla -- multiple vulnerabilities (44b6dfbf-4ef7-4d52-ad52-2b1b05d81272)NessusFreeBSD Local Security Checks
critical
125343Debian DSA-4448-1 : firefox-esr - security updateNessusDebian Local Security Checks
critical
125339Ubuntu 16.04 LTS / 18.04 LTS / 18.10 / 19.04 : Firefox vulnerabilities (USN-3991-1)NessusUbuntu Local Security Checks
critical
700733Mozilla Firefox ESR < 60.7 Multiple VulnerabilitiesNessus Network MonitorWeb Clients
high
700727Mozilla Firefox < 67.0 Multiple VulnerabilitiesNessus Network MonitorWeb Clients
high
700742Mozilla Thunderbird < 60.7 Multiple VulnerabilitiesNessus Network MonitorSMTP Clients
high