CVE-2019-11746: Use After Free
Published Sep 3, 2019
·Updated
A use-after-free vulnerability can occur while manipulating video elements if the body is freed while still in use. This results in a potentially exploitable crash.
Affected Software
14 affected componentsFixes available
Mozilla Thunderbird<68.1
68.1
Mozilla Thunderbird<60.9
60.9
Mozilla Firefox<69.0
Mozilla Firefox ESR<60.9.0
Mozilla Firefox ESR>=68.0<68.1.0
Mozilla Thunderbird<60.9.0
Mozilla Thunderbird>=68.0<68.1.0
Mozilla Firefox ESR<68.1
68.1
Mozilla Firefox<69
69
Mozilla Firefox ESR<60.9
60.9
Mozilla Firefox<60.9.0
debian/firefox
147.0.4-1
debian/firefox-esr
115.14.0esr-1~deb11u1140.7.0esr-1~deb11u1128.14.0esr-1~deb12u1140.8.0esr-1~deb12u1140.4.0esr-1~deb13u1140.8.0esr-1~deb13u1140.7.0esr-1
debian/thunderbird
1:115.12.0-1~deb11u11:140.7.1esr-1~deb11u11:140.6.0esr-1~deb12u11:140.7.1esr-1~deb12u11:140.6.0esr-1~deb13u11:140.7.1esr-1~deb13u11:140.7.1esr-1
Event History
Sep 3, 2019
CVE Published
12:00 AM
Sep 27, 2019
CVE Published
via MITRE·05:16 PM
Data Sourced
via MITRE·05:16 PM
DescriptionWeakness
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeaknessAffected Software
Aug 4, 2024
Data Sourced
via Launchpad·11:11 PM
Description
Nov 26, 2025
Data Sourced
via Ubuntu·06:15 PM
RemedyDescriptionSeverityAffected Software
Feb 25, 2026
Data Sourced
via Debian·10:34 PM
DescriptionAffected Software
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2019-11739
- CVE-2019-11746
- CVE-2019-11744
- CVE-2019-11742
- CVE-2019-11752
- CVE-2019-11743
- CVE-2019-11740
- CVE-2019-11751
- CVE-2019-11736
- CVE-2019-11753
- CVE-2019-9812
- CVE-2019-11748
- CVE-2019-11749
- CVE-2019-11750
- CVE-2019-11738
- CVE-2019-11747
- CVE-2019-11735
- CVE-2019-11741
- CVE-2019-5849
- CVE-2019-11737
- CVE-2019-11734
- CVE-2019-11758
Frequently Asked Questions
1
What is CVE-2019-11746?
CVE-2019-11746 is a use-after-free vulnerability that can occur while manipulating video elements in certain versions of Mozilla Firefox and Thunderbird.
2
How does CVE-2019-11746 affect Mozilla Firefox and Thunderbird?
CVE-2019-11746 affects certain versions of Mozilla Firefox ESR, Firefox, and Thunderbird.
3
How severe is CVE-2019-11746?
CVE-2019-11746 has a severity rating of 7 (high).
4
What is the potential impact of CVE-2019-11746?
CVE-2019-11746 can potentially lead to a crash, which may be exploitable.
5
How can I fix CVE-2019-11746?
To fix CVE-2019-11746, update your Mozilla Firefox or Thunderbird to the version mentioned in the advisory.