CVE-2019-9811: Debian Linux
High severity, CVSS 8.3. EPSS: 2.6% chance of exploitation in the next 30 days.
As part of a winning Pwn2Own entry, a researcher demonstrated a sandbox escape by installing a malicious language pack and then opening a browser feature that used the compromised translation. This vulnerability affects Firefox ESR < 60.8, Firefox < 68, and Thunderbird < 60.8.
Affected products
- Debian Debian Linux: version 8.0 only
- Mozilla Firefox: before 68.0 (fixed in 68.0)
- Mozilla Firefox ESR: before 60.8 (fixed in 60.8)
- Mozilla Thunderbird: before 60.8 (fixed in 60.8)
- Novell Suse Package Hub For Suse Linux Enterprise: version 12 only
- Opensuse Leap: version 15.0 only; version 15.1 only
Published 2019-07-23. Last modified 2026-06-17.