6.8
CVSSv2

CVE-2019-17008

Published: 08/01/2020 Updated: 16/01/2020
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

A use-after-free vulnerability has been found in Firefox prior to 71.0. When using nested workers, a use-after-free could occur during worker destruction. This resulted in a potentially exploitable crash.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

mozilla firefox

mozilla firefox esr

mozilla thunderbird

opensuse leap 15.1

Vendor Advisories

Multiple security issues have been found in the Mozilla Firefox web browser, which could potentially result in the execution of arbitrary code For the oldstable distribution (stretch), these problems have been fixed in version 6830esr-1~deb9u1 For the stable distribution (buster), these problems have been fixed in version 6830esr-1~deb10u1 W ...
Multiple security issues have been found in Thunderbird which could potentially result in the execution of arbitrary code For the oldstable distribution (stretch), these problems have been fixed in version 1:6830-2~deb9u1 For the stable distribution (buster), these problems have been fixed in version 1:6830-2~deb10u1 We recommend that you up ...
Synopsis Important: thunderbird security update Type/Severity Security Advisory: Important Topic An update for thunderbird is now available for Red Hat Enterprise Linux 8Red Hat Product Security has rated this update as having a security impact of Important A Common Vulnerability Scoring System (CVSS) bas ...
Synopsis Important: thunderbird security update Type/Severity Security Advisory: Important Topic An update for thunderbird is now available for Red Hat Enterprise Linux 7Red Hat Product Security has rated this update as having a security impact of Important A Common Vulnerability Scoring System (CVSS) bas ...
Synopsis Important: thunderbird security update Type/Severity Security Advisory: Important Topic An update for thunderbird is now available for Red Hat Enterprise Linux 6Red Hat Product Security has rated this update as having a security impact of Important A Common Vulnerability Scoring System (CVSS) bas ...
Synopsis Critical: firefox security update Type/Severity Security Advisory: Critical Topic An update for firefox is now available for Red Hat Enterprise Linux 7Red Hat Product Security has rated this update as having a security impact of Critical A Common Vulnerability Scoring System (CVSS) base score, wh ...
Synopsis Critical: firefox security update Type/Severity Security Advisory: Critical Topic An update for firefox is now available for Red Hat Enterprise Linux 6Red Hat Product Security has rated this update as having a security impact of Critical A Common Vulnerability Scoring System (CVSS) base score, wh ...
Synopsis Critical: firefox security update Type/Severity Security Advisory: Critical Topic An update for firefox is now available for Red Hat Enterprise Linux 8Red Hat Product Security has rated this update as having a security impact of Critical A Common Vulnerability Scoring System (CVSS) base score, wh ...
Synopsis Critical: firefox security update Type/Severity Security Advisory: Critical Topic An update for firefox is now available for Red Hat Enterprise Linux 80 Update Services for SAP SolutionsRed Hat Product Security has rated this update as having a security impact of Critical A Common Vulnerability ...
Synopsis Important: thunderbird security update Type/Severity Security Advisory: Important Topic An update for thunderbird is now available for Red Hat Enterprise Linux 80 Update Services for SAP SolutionsRed Hat Product Security has rated this update as having a security impact of Important A Common Vul ...
Firefox could be made to crash or run programs as your login if it opened a malicious website ...
Firefox could be made to crash or run programs as your login if it opened a malicious website ...
Several security issues were fixed in Thunderbird ...
Several security issues were fixed in Thunderbird ...
The plain text serializer used a fixed-size array for the number of <ol> elements it could process; however it was possible to overflow the static-sized array leading to memory corruption and a potentially exploitable crash This vulnerability affects Thunderbird < 683, Firefox ESR < 683, and Firefox < 71 (CVE-2019-17005) Under ce ...
A use-after-free vulnerability has been found in Firefox before 710 When using nested workers, a use-after-free could occur during worker destruction This resulted in a potentially exploitable crash ...
Mozilla Foundation Security Advisory 2019-37 Security Vulnerabilities fixed in - Firefox ESR 683 Announced December 3, 2019 Impact high Products Firefox ESR Fixed in Firefox ESR 683 ...
Mozilla Foundation Security Advisory 2019-36 Security Vulnerabilities fixed in - Firefox 71 Announced December 3, 2019 Impact high Products Firefox Fixed in Firefox 71 ...
Mozilla Foundation Security Advisory 2019-38 Security Vulnerabilities fixed in - Thunderbird 683 Announced December 3, 2019 Impact high Products Thunderbird Fixed in Thunderbird 683 ...