CVE-2019-11745 describes a heap corruption vulnerability in Mozilla products, including Firefox and Thunderbird, due to an out-of-bounds write during block cipher encryption when data is smaller than the block size. This high-severity flaw (CVSS 8.8) is network-exploitable with low complexity, requiring user interaction, and could lead to significant confidentiality, integrity, and availability impacts. While no active exploitation or public exploit code is currently reported, and community discussion is minimal, affected organizations should prioritize patching due to the potential for a remotely exploitable crash.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 71.0CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:* | ||
< 68.3CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox_esr:*:*:*:*:*:*:*:* | ||
< 68.3.0CPE matchmatch criteria | cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:* | ||
15.1CPE matchmatch criteria | cpe:2.3:o:opensuse:leap:15.1:*:*:*:*:*:*:* | ||
16.04CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.