CVE-2019-11691: Use After Free
A use-after-free vulnerability can occur when working with XMLHttpRequest (XHR) in an event loop, causing the XHR main thread to be called after it has been freed. This results in a potentially exploitable crash.
External Reference:
https://www.mozilla.org/en-US/security/advisories/mfsa2019-14/#CVE-2019-11691
Other sources
A use-after-free vulnerability can occur when working with XMLHttpRequest (XHR) in an event loop, causing the XHR main thread to be called after it has been freed. This results in a potentially exploitable crash.
— Mozilla
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2019-9815
- CVE-2019-9816
- CVE-2019-9817
- CVE-2019-9818
- CVE-2019-9819
- CVE-2019-9820
- CVE-2019-11691
- CVE-2019-11692
- CVE-2019-11693
- CVE-2019-7317
- CVE-2019-9797
- CVE-2018-18511
- CVE-2019-11694
- CVE-2019-11698
- CVE-2019-5798
- CVE-2019-9800
- CVE-2019-9821
- CVE-2019-11695
- CVE-2019-11696
- CVE-2019-11697
- CVE-2019-11700
- CVE-2019-11699
- CVE-2019-11701
- CVE-2019-9814
Frequently Asked Questions
What is CVE-2019-11691?
CVE-2019-11691 is a use-after-free vulnerability that can occur when working with XMLHttpRequest (XHR) in an event loop, causing a potentially exploitable crash in Thunderbird < 60.7, Firefox < 67, and Firefox ESR < 60.7.
How does CVE-2019-11691 affect Mozilla Firefox?
CVE-2019-11691 affects Mozilla Firefox versions up to exclusive 67.
How does CVE-2019-11691 affect Mozilla Firefox ESR?
CVE-2019-11691 affects Mozilla Firefox ESR versions up to exclusive 60.7.
How does CVE-2019-11691 affect Thunderbird?
CVE-2019-11691 affects Thunderbird versions up to exclusive 60.7.
What is the severity of CVE-2019-11691?
The severity of CVE-2019-11691 is critical, with a CVSS score of 9.8.