CVE-2019-17021: Mozilla Firefox

Medium severity, CVSS 5.3. EPSS: 1.9% chance of exploitation in the next 30 days.

During the initialization of a new content process, a race condition occurs that can allow a content process to disclose heap addresses from the parent process. *Note: this issue only occurs on Windows. Other operating systems are unaffected.*. This vulnerability affects Firefox ESR < 68.4 and Firefox < 72.

Affected products

  • Mozilla Firefox: before 72.0 (fixed in 72.0)
  • Mozilla Firefox ESR: before 68.4 (fixed in 68.4)
  • Opensuse Leap: version 15.1 only

Published 2020-01-08. Last modified 2026-06-17.