CVE-2019-11743: Medium severity Mozilla Thunderbird vulnerability
Last updated 25 August 2025
Other sources
Navigation events were not fully adhering to the W3C's "Navigation-Timing Level 2" draft specification in some instances for the unload event, which restricts access to detailed timing attributes to only be same-origin. This resulted in potential cross-origin information exposure of history through timing side-channel attacks.
— Mozilla
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2019-11739
- CVE-2019-11746
- CVE-2019-11744
- CVE-2019-11742
- CVE-2019-11752
- CVE-2019-11743
- CVE-2019-11740
- CVE-2019-11751
- CVE-2019-11736
- CVE-2019-11753
- CVE-2019-9812
- CVE-2019-11748
- CVE-2019-11749
- CVE-2019-11750
- CVE-2019-11738
- CVE-2019-11747
- CVE-2019-11735
- CVE-2019-11741
- CVE-2019-5849
- CVE-2019-11737
- CVE-2019-11734
- CVE-2019-11758
Frequently Asked Questions
What is the severity of CVE-2019-11743?
The severity of CVE-2019-11743 is medium.
Which software versions are affected by CVE-2019-11743?
The software versions affected by CVE-2019-11743 are Firefox ESR versions up to 68.1, Firefox versions up to 69, Thunderbird versions up to 60.9, and Thunderbird versions up to 68.1.
How can I fix CVE-2019-11743?
To fix CVE-2019-11743, update to Mozilla Firefox ESR version 68.1, Mozilla Firefox version 69, Mozilla Thunderbird version 60.9, or Mozilla Thunderbird version 68.1.
What is the W3C's "Navigation-Timing Level 2" draft specification?
The W3C's "Navigation-Timing Level 2" is a draft specification that defines timing attributes for navigation events in web browsers.
Where can I find more information about CVE-2019-11743?
More information about CVE-2019-11743 can be found at the following references: [Mozilla Bugzilla](https://bugzilla.mozilla.org/show_bug.cgi?id=1560495), [W3C Navigation-Timing Level 2](https://w3c.github.io/navigation-timing), and [Mozilla Security Advisory](https://www.mozilla.org/en-US/security/advisories/mfsa2019-29/).