CVE-2019-11692: Use After Free
A use-after-free vulnerability can occur when listeners are removed from the event listener manager while still in use, resulting in a potentially exploitable crash.
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2019-9815
- CVE-2019-9816
- CVE-2019-9817
- CVE-2019-9818
- CVE-2019-9819
- CVE-2019-9820
- CVE-2019-11691
- CVE-2019-11692
- CVE-2019-11693
- CVE-2019-7317
- CVE-2019-9797
- CVE-2018-18511
- CVE-2019-11694
- CVE-2019-11698
- CVE-2019-5798
- CVE-2019-9800
- CVE-2019-9821
- CVE-2019-11695
- CVE-2019-11696
- CVE-2019-11697
- CVE-2019-11700
- CVE-2019-11699
- CVE-2019-11701
- CVE-2019-9814
Frequently Asked Questions
What is CVE-2019-11692?
CVE-2019-11692 is a use-after-free vulnerability that can occur when listeners are removed from the event listener manager while still in use.
Which software is affected by CVE-2019-11692?
CVE-2019-11692 affects Thunderbird < 60.7, Firefox < 67, and Firefox ESR < 60.7.
How severe is CVE-2019-11692?
CVE-2019-11692 has a severity rating of 9.8 out of 10. It is classified as critical.
How can I fix CVE-2019-11692?
To fix CVE-2019-11692, update Thunderbird to version 60.7 or later, update Firefox to version 67 or later, or update Firefox ESR to version 60.7 or later.
Where can I find more information about CVE-2019-11692?
You can find more information about CVE-2019-11692 on the Mozilla Bugzilla page and the Mozilla Security Advisories page.