VDB

GCVE-110-MAGEIA-2019-190

GCVE-110-MAGEIA-2019-190
Advisory Published
Vulnetix · Advisory published June 10, 2019
Updated thunderbird packages fixes bugs and security vulnerabilities: Cross-origin theft of images with ImageBitmapRenderingContext. (CVE-2018-18511) Out-of-bounds read in Skia. (CVE-2019-5798) Use-after-free in png_image_free of libpng library. (CVE-2019-7317) Cross-origin theft of images with createImageBitmap. (CVE-2019-9797) Memory safety bugs fixed in Thunderbird 60.7. (CVE-2019-9800) Type confusion with object groups and UnboxedObjects. (CVE-2019-9816) Stealing of cross-domain images using canvas. (CVE-2019-9817) Use-after-free in crash generation server. (CVE-2019-9818) Compartment mismatch with fetch API. (CVE-2019-9819) Use-after-free of ChromeEventHandler by DocShell. (CVE-2019-9820) Use-after-free in XMLHttpRequest. (CVE-2019-11691) Use-after-free removing listeners in the event listener manager. (CVE-2019-11692) Buffer overflow in WebGL bufferdata on Linux. (CVE-2019-11693) Theft of user history data through drag and drop of hyperlinks to and from bookmarks. (CVE-2019-11698) Inline-PGP messages that allows an attacker to have Enigmail display a correctly signed or encrypted message info, but display a different unauthenticated text.

Affected Products

VendorProductVersionsPlatforms
Mageiathunderbird-l10n0 (affected), 60.7.0-1.mga6 (unaffected), 0 (affected), 60.7.0-1.mga6 (unaffected)
Mageiax11-driver-video-ati0 (affected), 19.1.0-1.mga7 (unaffected)
Mageiathunderbird0 (affected), 60.7.0-1.mga6 (unaffected), 0 (affected), 60.7.0-1.mga6 (unaffected)

Browse GCVE Records

77,606 records in the GCVE database · Updated August 8, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›