CVE-2019-9790: Use After Free
A use-after-free vulnerability can occur when a raw pointer to a DOM element on a page is obtained using JavaScript and the element is then removed while still in use. This results in a potentially exploitable crash.
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is CVE-2019-9790?
CVE-2019-9790 is a use-after-free vulnerability in Mozilla Firefox and Thunderbird.
How does CVE-2019-9790 occur?
CVE-2019-9790 occurs when a raw pointer to a DOM element is obtained using JavaScript and the element is then removed while still in use.
Which software is affected by CVE-2019-9790?
CVE-2019-9790 affects Thunderbird versions less than 60.6, Firefox ESR versions less than 60.6, and Firefox versions less than 66.
What is the severity of CVE-2019-9790?
CVE-2019-9790 has a severity rating of critical.
How can I fix CVE-2019-9790?
To fix CVE-2019-9790, update to Mozilla Firefox version 66 or higher, or update to Thunderbird version 60.6 or higher.