Skip to content
Appaloosa Scout

Vulnerability · NVD

CVE-2019-11740

HIGH 8.8

Mozilla developers and community members reported memory safety bugs present in Firefox 68, Firefox ESR 68, and Firefox 60.8. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firefox < 69, Thunderbird < 68.1, Thunderbird < 60.9, Firefox ESR < 60.9, and Firefox ESR < 68.1.

Attack vector : Network No privileges required
Show raw CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS 1.64% above median percentile 74.2%

Tracked apps referencing this CVE

For each app: the affected range, the fixing version, and where the tracked app stands today.

NVD references 5 distinct products for this CVE — only those tracked by Scout (mobile and desktop catalog apps) are listed above. Libraries, servers and out-of-scope products do not appear here. Full list on NVD ↗

Vulnerable CPE configurations (2)
Vendor Product Versions
mozilla thunderbird
All platforms (wildcard)
<60.9.0
mozilla thunderbird
All platforms (wildcard)
≥68.0 <68.1.0
View on NVD ↗ Advisory · bugzilla.mozilla.org Advisory · www.mozilla.org