Back

CRITICAL

Mozilla: Use-after-free parsing HTML5 stream

Published Feb 5, 2019

Description

A use-after-free vulnerability can occur while parsing an HTML5 stream in concert with custom HTML elements. This results in the stream parser object being freed while still in use, leading to a potentially exploitable crash. This vulnerability affects Thunderbird < 60.5, Firefox ESR < 60.5, and Firefox < 65.

Affected products

Remediation

No remediation recorded yet.

Metrics

Weaknesses (1)

References (22)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mozilla
Published Feb 5, 2019
Updated Aug 5, 2024
Reserved Oct 19, 2018
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Critical
Public date Jan 29, 2019