CVE-2019-17012: High severity Mozilla Firefox vulnerability
Last updated 25 August 2025
Other sources
Mozilla developers Christoph Diehl, Nathan Froyd, Jason Kratzer, Christian Holler, Karl Tomlinson, Tyson Smith reported memory safety bugs present in Firefox 70 and Firefox ESR 68.2. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code.
Mozilla developers reported memory safety bugs present in Firefox 70 and Firefox ESR 68.2. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Thunderbird < 68.3, Firefox ESR < 68.3, and Firefox < 71.
— Launchpad
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2019-17012?
The severity of CVE-2019-17012 is high.
Which software is affected by CVE-2019-17012?
Mozilla Thunderbird up to version 68.3, Mozilla Firefox up to version 71, and Mozilla Firefox ESR up to version 68.3 are affected by CVE-2019-17012.
What is the remedy for CVE-2019-17012?
The remedy for CVE-2019-17012 is to update Mozilla Thunderbird to version 68.3, Mozilla Firefox to version 71, and Mozilla Firefox ESR to version 68.3.
What are the memory safety bugs reported in CVE-2019-17012?
The memory safety bugs reported in CVE-2019-17012 are memory corruption bugs in Firefox 70 and Firefox ESR 68.2.
Are there any references for CVE-2019-17012?
Yes, you can find references for CVE-2019-17012 at the following links: [Bugzilla](https://bugzilla.mozilla.org/buglist.cgi?bug_id=1449736%2C1533957%2C1560667%2C1567209%2C1580288%2C1585760%2C1592502), [Mozilla Security Advisories - MFSA2019-38](https://www.mozilla.org/en-US/security/advisories/mfsa2019-38/), [Mozilla Security Advisories - MFSA2019-36](https://www.mozilla.org/en-US/security/advisories/mfsa2019-36/)