CVE-2019-11743 is a low-severity vulnerability affecting Mozilla Firefox, Firefox ESR, and Thunderbird versions prior to 69 and 68.1 respectively. It involves a timing side-channel attack where navigation events did not fully adhere to W3C specifications, potentially exposing cross-origin history information. The CVSS score is 3.7 (LOW), indicating a network-based attack with high complexity, leading to low confidentiality impact. There is no evidence of active exploitation, no public exploit code (Metasploit, Nuclei, ExploitDB), and minimal community discussion or media coverage, despite one article mentioning a critical code execution flaw in Firefox 69, which is likely a different vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 60.9.0CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:* | ||
< 69.0CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:* | ||
>= 68.0, < 68.1.0CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox_esr:*:*:*:*:*:*:*:* | ||
< 60.9.0CPE matchmatch criteria | cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:* | ||
>= 68.0, < 68.1.0CPE matchmatch criteria | cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.3 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.