CVE-2019-17010: Race Condition
Last updated 25 August 2025
Other sources
Under certain conditions, when checking the Resist Fingerprinting preference during device orientation checks, a race condition could have caused a use-after-free and a potentially exploitable crash.
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is CVE-2019-17010?
CVE-2019-17010 is a vulnerability in Mozilla Thunderbird, Firefox, and Firefox ESR that could lead to a potentially exploitable crash.
How severe is CVE-2019-17010?
CVE-2019-17010 has a severity level of medium.
Which software versions are affected by CVE-2019-17010?
CVE-2019-17010 affects Mozilla Thunderbird up to version 68.3, Mozilla Firefox up to version 71, and Mozilla Firefox ESR up to version 68.3.
How can I fix CVE-2019-17010?
To fix CVE-2019-17010, it is recommended to update Mozilla Thunderbird to version 68.3, Mozilla Firefox to version 71, and Mozilla Firefox ESR to version 68.3.
Where can I find more information about CVE-2019-17010?
You can find more information about CVE-2019-17010 in the following references: [Mozilla Bugzilla](https://bugzilla.mozilla.org/show_bug.cgi?id=1581084), [Mozilla Security Advisories](https://www.mozilla.org/en-US/security/advisories/mfsa2019-38/), [Mozilla Security Advisories](https://www.mozilla.org/en-US/security/advisories/mfsa2019-36/).