CVE-2019-11764: High severity Mozilla Firefox vulnerability
Last updated 25 August 2025
Other sources
Mozilla developers and community members Bob Clary, Jason Kratzer, Aaron Klotz, Iain Ireland, Tyson Smith, Christian Holler, Steve Fink, Honza Bambas, Byron Campen, and Cristian Brindusan reported memory safety bugs present in Firefox 69 and Firefox ESR 68.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could be exploited to run arbitrary code.
— Mozilla
Mozilla developers and community members reported memory safety bugs present in Firefox 69 and Firefox ESR 68.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could be exploited to run arbitrary code.
External Reference:
https://www.mozilla.org/en-US/security/advisories/mfsa2019-33/#CVE-2019-11764
— Red Hat
Mozilla developers and community members reported memory safety bugs present in Firefox 69 and Firefox ESR 68.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could be exploited to run arbitrary code. This vulnerability affects Firefox < 70, Thunderbird < 68.2, and Firefox ESR < 68.2.
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is CVE-2019-11764?
CVE-2019-11764 is a vulnerability discovered in Firefox 69 and Firefox ESR 68.1 that allows memory safety bugs to be exploited.
What is the severity of CVE-2019-11764?
CVE-2019-11764 has a severity rating of 8.8, which is classified as critical.
Which software versions are affected by CVE-2019-11764?
Firefox versions 69 and Firefox ESR 68.1 are affected by CVE-2019-11764.
How can CVE-2019-11764 be fixed?
To fix CVE-2019-11764, you should update Firefox to version 68.2 or later.
Where can I find more information about CVE-2019-11764?
You can find more information about CVE-2019-11764 on the Mozilla Bugzilla and Mozilla security advisories websites.