CVE-2019-9811
published 2019-07-23CVE-2019-9811: As part of a winning Pwn2Own entry, a researcher demonstrated a sandbox escape by installing a malicious language pack and then opening a browser feature that…
high8.3CVSS 3.1
AVNACHPRNUIRSCCHIHAH
As part of a winning Pwn2Own entry, a researcher demonstrated a sandbox escape by installing a malicious language pack and then opening a browser feature that used the compromised translation. This vulnerability affects Firefox ESR < 60.8, Firefox < 68, and Thunderbird < 60.8.
Affected
23 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | firefox | < firefox 68.0-1 (sid) | firefox 68.0-1 (sid) |
| debian | firefox-esr | < firefox 68.0-1 (sid) | firefox 68.0-1 (sid) |
| debian | thunderbird | < firefox 68.0-1 (sid) | firefox 68.0-1 (sid) |
| mozilla | firefox | < 68.0 | 68.0 |
| mozilla | firefox | >= 0 < 68.0+build3-0ubuntu0.16.04.1 | 68.0+build3-0ubuntu0.16.04.1 |
| mozilla | firefox | >= 0 < 68.0.1+build1-0ubuntu0.16.04.1 | 68.0.1+build1-0ubuntu0.16.04.1 |
| mozilla | firefox | >= 0 < 68.0+build3-0ubuntu0.18.04.1 | 68.0+build3-0ubuntu0.18.04.1 |
| mozilla | firefox | >= 0 < 68.0.1+build1-0ubuntu0.18.04.1 | 68.0.1+build1-0ubuntu0.18.04.1 |
| mozilla | firefox | >= unspecified < 68 | 68 |
| mozilla | firefox_esr | < 60.8 | 60.8 |
| mozilla | firefox_esr | >= unspecified < 60.8 | 60.8 |
| mozilla | thunderbird | < 60.8 | 60.8 |
| mozilla | thunderbird | >= 0 < 1:60.8.0-1 | 1:60.8.0-1 |
| mozilla | thunderbird | >= 0 < 1:60.8.0-1 | 1:60.8.0-1 |
| mozilla | thunderbird | >= 0 < 1:60.8.0-1 | 1:60.8.0-1 |
| mozilla | thunderbird | >= 0 < 1:60.8.0-1 | 1:60.8.0-1 |
| mozilla | thunderbird | >= 0 < 1:60.8.0+build1-0ubuntu0.16.04.2 | 1:60.8.0+build1-0ubuntu0.16.04.2 |
| mozilla | thunderbird | >= 0 < 1:60.8.0+build1-0ubuntu0.18.04.1 | 1:60.8.0+build1-0ubuntu0.18.04.1 |
| mozilla | thunderbird | >= unspecified < 60.8 | 60.8 |
| novell | suse_package_hub_for_suse_linux_enterprise | — | — |
| opensuse | leap | — | — |
| opensuse | leap | — | — |
CVSS provenance
nvdv3.18.3HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H
osv9.8CRITICAL