When manipulating user events in nested loops while opening a document through script, it is possible to trigger a potentially exploitable crash due to poor event handling. This vulnerability affects Firefox < 63, Firefox ESR < 60.3, and Thunderbird < 60.3.
CVSS Details
- CVSS 3.1 Base Score: 9.8
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | alpine-linux-upgrade-firefox-esr | Apr 16, 2019 | Feb 28, 2019 |
| Amazon Linux Ami 2 | amazon-linux-ami-2-upgrade-thunderbirdamazon-linux-ami-2-upgrade-thunderbird-debuginfo | Apr 27, 2020 | Feb 28, 2019 | |
| Arch Linux | View advisory ↗View advisory ↗View advisory ↗View advisory ↗View advisory ↗View advisory ↗View advisory ↗View advisory ↗View advisory ↗View advisory ↗View advisory ↗View advisory ↗View advisory ↗View advisory ↗View advisory ↗View advisory ↗View advisory ↗View advisory ↗View advisory ↗View advisory ↗View advisory ↗View advisory ↗View advisory ↗View advisory ↗ | arch-linux-upgrade-latest | Jul 11, 2025 | Feb 28, 2019 |
| Centos_linux | — | centos-upgrade-firefoxcentos-upgrade-firefox-debuginfocentos-upgrade-thunderbirdcentos-upgrade-thunderbird-debuginfo | Oct 27, 2018 | Oct 23, 2018 |
| Debian | debian-upgrade-firefox-esrdebian-upgrade-thunderbird | Oct 25, 2018 | Oct 23, 2018 | |
| Freebsd | freebsd-upgrade-package-firefoxfreebsd-upgrade-package-waterfoxfreebsd-upgrade-package-seamonkeyfreebsd-upgrade-package-linux-seamonkeyfreebsd-upgrade-package-firefox-esrfreebsd-upgrade-package-linux-firefoxfreebsd-upgrade-package-libxulfreebsd-upgrade-package-thunderbirdfreebsd-upgrade-package-linux-thunderbird | Oct 24, 2018 | Oct 23, 2018 | |
| Gentoo Linux | gentoo-linux-upgrade-mail-client-thunderbirdgentoo-linux-upgrade-mail-client-thunderbird-bingentoo-linux-upgrade-www-client-firefoxgentoo-linux-upgrade-www-client-firefox-bin | Nov 9, 2018 | Nov 9, 2018 | |
| Huawei Euleros 2_0_sp2 | huawei-euleros-2_0_sp2-upgrade-firefox | Oct 4, 2019 | Feb 28, 2019 | |
| Huawei Euleros 2_0_sp3 | huawei-euleros-2_0_sp3-upgrade-firefox | Oct 4, 2019 | Feb 28, 2019 | |
| Mfsa2018 26 | mozilla-firefox-upgrade-63_0 | Oct 24, 2018 | Oct 23, 2018 | |
| Mfsa2018 27 | mozilla-firefox-esr-upgrade-60_3 | Oct 24, 2018 | Oct 23, 2018 | |
| Mozilla Thunderbird | mozilla-thunderbird-upgrade-60_3 | Nov 1, 2018 | Oct 31, 2018 | |
| Oracle Solaris | oracle-solaris-11-4-upgrade-mail-thunderbird-60-6-1-11-4-9-0-1-2-0oracle-solaris-11-4-upgrade-mail-thunderbird-plugin-thunderbird-lightning-60-6-1-11-4-9-0-1-2-0oracle-solaris-11-4-upgrade-web-browser-firefox-60-5-0-11-4-6-0-1-4-0oracle-solaris-11-4-upgrade-web-data-firefox-bookmarks-60-5-0-11-4-6-0-1-4-0 | Feb 20, 2019 | Feb 20, 2019 | |
| Oracle_linux | — | oracle-linux-upgrade-firefoxoracle-linux-upgrade-thunderbird | Nov 2, 2018 | Oct 23, 2018 |
| Redhat_linux | — | redhat-upgrade-firefoxredhat-upgrade-firefox-debuginforedhat-upgrade-thunderbirdredhat-upgrade-thunderbird-debuginfo | Oct 25, 2018 | Oct 24, 2018 |
| Suse | — | suse-upgrade-mozillafirefoxsuse-upgrade-mozillafirefox-branding-upstreamsuse-upgrade-mozillafirefox-buildsymbolssuse-upgrade-mozillafirefox-develsuse-upgrade-mozillafirefox-translations-commonsuse-upgrade-mozillafirefox-translations-othersuse-upgrade-mozillathunderbirdsuse-upgrade-mozillathunderbird-buildsymbolssuse-upgrade-mozillathunderbird-translations-commonsuse-upgrade-mozillathunderbird-translations-other | Oct 26, 2018 | Oct 23, 2018 |
| Ubuntu | ubuntu-upgrade-firefoxubuntu-upgrade-thunderbird | Nov 7, 2018 | Oct 23, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub