Back

CRITICAL

Mozilla: Use-after-free when removing in-use DOM elements

Published Apr 26, 2019

Description

A use-after-free vulnerability can occur when a raw pointer to a DOM element on a page is obtained using JavaScript and the element is then removed while still in use. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 60.6, Firefox ESR < 60.6, and Firefox < 66.

Affected products

Remediation

Red Hat statement

In general, this flaw be exploited through email in the Thunderbird product because scripting is disabled when reading mail, but are potentially risks in browser or browser-like contexts.

Weaknesses (1)

References (12)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mozilla
Published Apr 26, 2019
Updated Aug 4, 2024
Reserved Mar 14, 2019
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Critical
Public date Mar 20, 2019
ENISA EUVD
Assigner mozilla
Published Apr 26, 2019
Updated Aug 4, 2024
Exploited since n/a
EUVD-2019-19152