CVE-2019-9814Out-of-bounds Write in Mozilla Firefox

Severity
9.8CRITICALNVD
OSV7.5OSV5.5
EPSS
0.6%
top 30.31%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 23
Latest updateApr 2

Description

Mozilla developers and community members reported memory safety bugs present in Firefox 66. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firefox < 67.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages5 packages

CVEListV5mozilla/firefoxunspecified67
NVDmozilla/firefox< 67.0
Ubuntumozilla/firefox< 67.0+build2-0ubuntu0.16.04.1+5
debiandebian/firefox< firefox 67.0-2 (sid)
Ubuntucairographics/cairo< 1.16.0-5ubuntu2.1+4

🔴Vulnerability Details

7
OSV
cairo vulnerabilities2026-04-02
GHSA
GHSA-x8mw-7jxq-c26v: Mozilla developers and community members reported memory safety bugs present in Firefox 662022-05-24
OSV
cairo vulnerabilities2022-05-10
OSV
firefox regression2019-06-14
OSV
firefox regression2019-06-06

📋Vendor Advisories

4
Ubuntu
Firefox regression2019-06-14
Ubuntu
Firefox regression2019-06-06
Ubuntu
Firefox vulnerabilities2019-05-21
Debian
CVE-2019-9814: firefox - Mozilla developers and community members reported memory safety bugs present in ...2019