CVE-2019-9818

CVSS v3.1 8.3 (High)
83% Progress
CVSS v2.0 5.1 (Medium)
51% Progress
EPSS 0.27 % (68th)
0.27% Progress
Affected Products 4
Advisories 11

A race condition is present in the crash generation server used to generate data for the crash reporter. This issue can lead to a use-after-free in the main process, resulting in a potentially exploitable crash and a sandbox escape. Note: this vulnerability only affects Windows. Other operating systems are unaffected.. This vulnerability affects Thunderbird < 60.7, Firefox < 67, and Firefox ESR < 60.7.

Weaknesses
CWE-362
Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CWE-416
Use After Free
CVE Status
PUBLISHED
CNA
Mozilla Corporation
Published Date
2019-07-23 14:15:17
(5 years ago)
Updated Date
2021-07-21 11:39:23
(3 years ago)

Affected Products

Loading...
Loading...
Loading...

Configuration #1

AND
    CPE23 From Up To
OR  
  Mozilla Firefox prior 67.0 version cpe:2.3:a:mozilla:firefox < 67.0
OR  
  Running on/with
  Mozilla Firefox Esr prior 60.7 version cpe:2.3:a:mozilla:firefox_esr < 60.7
OR  
  Running on/with
  Mozilla Thunderbird prior 60.7 version cpe:2.3:a:mozilla:thunderbird < 60.7
OR  
  Running on/with
  Microsoft Windows cpe:2.3:o:microsoft:windows:-
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...