Severity
8.8HIGHNVD
OSV7.5
EPSS
0.8%
top 25.10%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 8
Latest updateMay 24

Description

Mozilla community member Philipp reported a memory safety bug present in Firefox 68 when 360 Total Security was installed. This bug showed evidence of memory corruption in the accessibility engine and we presume that with enough effort that it could be exploited to run arbitrary code. This vulnerability affects Firefox < 69, Thunderbird < 68.2, and Firefox ESR < 68.2.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages7 packages

NVDmozilla/firefox< 69.0
CVEListV5mozilla/firefoxbefore 69
CVEListV5mozilla/firefox_esrbefore 68.2

Also affects: Ubuntu Linux 16.04

🔴Vulnerability Details

5
GHSA
GHSA-vq8v-gqr8-jrr5: Mozilla community member Philipp reported a memory safety bug present in Firefox 68 when 360 Total Security was installed2022-05-24
OSV
thunderbird vulnerabilities2020-04-21
CVEList
CVE-2019-11758: Mozilla community member Philipp reported a memory safety bug present in Firefox 68 when 360 Total Security was installed2020-01-08
OSV
thunderbird regression2019-12-10
OSV
thunderbird vulnerabilities2019-11-26

📋Vendor Advisories

5
Ubuntu
Thunderbird vulnerabilities2020-04-21
Ubuntu
Thunderbird regression2019-12-10
Ubuntu
Thunderbird vulnerabilities2019-11-26
Red Hat
Mozilla: Potentially exploitable crash due to 360 Total Security2019-10-22
Debian
CVE-2019-11758: firefox-esr - Mozilla community member Philipp reported a memory safety bug present in Firefox...2019

💬Community

1
Bugzilla
CVE-2019-11758 Mozilla: Potentially exploitable crash due to 360 Total Security2019-10-23
CVE-2019-11758 — Out-of-bounds Write in Mozilla Firefox | cvebase