CVE-2019-9803
- EPSS 0.13%
- Veröffentlicht 26.04.2019 17:29:03
- Zuletzt bearbeitet 21.11.2024 04:52:20
The Upgrade-Insecure-Requests (UIR) specification states that if UIR is enabled through Content Security Policy (CSP), navigation to a same-origin URL must be upgraded to HTTPS. Firefox will incorrectly navigate to an HTTP URL rather than perform the...
CVE-2019-9804
- EPSS 1.15%
- Veröffentlicht 26.04.2019 17:29:03
- Zuletzt bearbeitet 21.11.2024 04:52:20
In Firefox Developer Tools it is possible that pasting the result of the 'Copy as cURL' command into a command shell on macOS will cause the execution of unintended additional bash script commands if the URL was maliciously crafted. This is the resul...
CVE-2019-9805
- EPSS 0.42%
- Veröffentlicht 26.04.2019 17:29:03
- Zuletzt bearbeitet 21.11.2024 04:52:20
A latent vulnerability exists in the Prio library where data may be read from uninitialized memory for some functions, leading to potential memory corruption. This vulnerability affects Firefox < 66.
CVE-2019-9806
- EPSS 0.34%
- Veröffentlicht 26.04.2019 17:29:03
- Zuletzt bearbeitet 21.11.2024 04:52:20
A vulnerability exists during authorization prompting for FTP transaction where successive modal prompts are displayed and cannot be immediately dismissed. This allows for a denial of service (DOS) attack. This vulnerability affects Firefox < 66.
CVE-2019-9807
- EPSS 0.2%
- Veröffentlicht 26.04.2019 17:29:03
- Zuletzt bearbeitet 21.11.2024 04:52:20
When arbitrary text is sent over an FTP connection and a page reload is initiated, it is possible to create a modal alert message with this text as the content. This could potentially be used for social engineering attacks. This vulnerability affects...
CVE-2019-9808
- EPSS 0.09%
- Veröffentlicht 26.04.2019 17:29:03
- Zuletzt bearbeitet 21.11.2024 04:52:21
If WebRTC permission is requested from documents with data: or blob: URLs, the permission notifications do not properly display the originating domain. The notification states "Unknown origin" as the requestee, leading to user confusion about which s...
CVE-2019-9809
- EPSS 0.51%
- Veröffentlicht 26.04.2019 17:29:03
- Zuletzt bearbeitet 21.11.2024 04:52:21
If the source for resources on a page is through an FTP connection, it is possible to trigger a series of modal alert messages for these resources through invalid credentials or locations. These messages cannot be immediately dismissed, allowing for ...
CVE-2019-9794
- EPSS 0.44%
- Veröffentlicht 26.04.2019 17:29:02
- Zuletzt bearbeitet 21.11.2024 04:52:19
A vulnerability was discovered where specific command line arguments are not properly discarded during Firefox invocation as a shell handler for URLs. This could be used to retrieve and execute files whose location is supplied through these command l...
CVE-2019-9795
- EPSS 0.76%
- Veröffentlicht 26.04.2019 17:29:02
- Zuletzt bearbeitet 21.11.2024 04:52:19
A vulnerability where type-confusion in the IonMonkey just-in-time (JIT) compiler could potentially be used by malicious JavaScript to trigger a potentially exploitable crash. This vulnerability affects Thunderbird < 60.6, Firefox ESR < 60.6, and Fir...
CVE-2019-9796
- EPSS 0.76%
- Veröffentlicht 26.04.2019 17:29:02
- Zuletzt bearbeitet 21.11.2024 04:52:19
A use-after-free vulnerability can occur when the SMIL animation controller incorrectly registers with the refresh driver twice when only a single registration is expected. When a registration is later freed with the removal of the animation controll...