Security Advisory

CVE-2019-17005

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2020-01-08 21:14:57
Last updated 2024-08-05 01:24:48
Assigner mozilla
CVSS score not scored
State PUBLISHED

Description

The plain text serializer used a fixed-size array for the number of <ol> elements it could process; however it was possible to overflow the static-sized array leading to memory corruption and a potentially exploitable crash. This vulnerability affects Thunderbird < 68.3, Firefox ESR < 68.3, and Firefox < 71.