CVE-2019-11740: High severity Mozilla Firefox vulnerability
Last updated 25 August 2025
Other sources
Mozilla developers and community members reported memory safety bugs present in Firefox 68, Firefox ESR 68, and Firefox 60.8. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firefox < 69, Thunderbird < 68.1, Thunderbird < 60.9, Firefox ESR < 60.9, and Firefox ESR < 68.1.
— MITRE
Mozilla developers and community members Tyson Smith and Nathan Froyd reported memory safety bugs present in Firefox 68, Firefox ESR 68, and Firefox 60.8. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code.
Mozilla developers and community members Tyson Smith and Nathan Froyd reported memory safety bugs present in Firefox 68, Firefox ESR 68, Firefox 60.8, Thunderbird 68, and Thunderbird 60.8. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code.
— Mozilla
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2019-11739
- CVE-2019-11746
- CVE-2019-11744
- CVE-2019-11742
- CVE-2019-11752
- CVE-2019-11743
- CVE-2019-11740
- CVE-2019-11751
- CVE-2019-11736
- CVE-2019-11753
- CVE-2019-9812
- CVE-2019-11748
- CVE-2019-11749
- CVE-2019-11750
- CVE-2019-11738
- CVE-2019-11747
- CVE-2019-11735
- CVE-2019-11741
- CVE-2019-5849
- CVE-2019-11737
- CVE-2019-11734
- CVE-2019-11758
Frequently Asked Questions
What is the severity of CVE-2019-11740?
The severity of CVE-2019-11740 is high.
Which software versions are affected by CVE-2019-11740?
Firefox 68, Firefox ESR 68, Firefox 60.8, Thunderbird 68, and Thunderbird 60.8 are affected by CVE-2019-11740.
What is the remedy for CVE-2019-11740?
Upgrade to Firefox 69, Firefox ESR 68.1, or Thunderbird 68.1 to mitigate the vulnerability.
Are there any references for CVE-2019-11740?
Yes, you can refer to the following links: [Bugzilla](https://bugzilla.mozilla.org/buglist.cgi?bug_id=1563133%2C1573160), [Mozilla Security Advisories](https://www.mozilla.org/en-US/security/advisories/mfsa2019-30/), [Mozilla Security Advisories](https://www.mozilla.org/en-US/security/advisories/mfsa2019-29/).