CVE-2019-17015: Mozilla Firefox

High severity, CVSS 8.8. EPSS: 1.8% chance of exploitation in the next 30 days.

During the initialization of a new content process, a pointer offset can be manipulated leading to memory corruption and a potentially exploitable crash in the parent process. *Note: this issue only occurs on Windows. Other operating systems are unaffected.*. This vulnerability affects Firefox ESR < 68.4 and Firefox < 72.

Affected products

  • Mozilla Firefox: before 72.0 (fixed in 72.0)
  • Mozilla Firefox ESR: before 68.4 (fixed in 68.4)

Published 2020-01-08. Last modified 2026-06-17.