CVE-2019-11759 is a critical buffer overflow vulnerability affecting Mozilla Firefox, Thunderbird, and Firefox ESR versions prior to 70, 68.2, and 68.2 respectively. An attacker could exploit this by causing 4 bytes of HMAC output to be written past a stack buffer, potentially leading to arbitrary code execution or a denial-of-service crash. With a CVSS score of 8.8 (High), this vulnerability is easily exploitable over a network with user interaction, enabling high impact to confidentiality, integrity, and availability. While no public exploits (Metasploit, Nuclei, ExploitDB) or active exploitation (KEV) have been identified, and community discussion is minimal, the potential for severe impact warrants prompt patching.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 70.0CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:* | ||
< 68.2CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox_esr:*:*:*:*:*:*:*:* | ||
< 68.2CPE matchmatch criteria | cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:* | ||
16.04CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:esm:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.