CVE-2019-11714
- EPSS 0.76%
- Published 23.07.2019 14:15:15
- Last modified 21.11.2024 04:21:38
Necko can access a child on the wrong thread during UDP connections, resulting in a potentially exploitable crash in some instances. This vulnerability affects Firefox < 68.
CVE-2019-11715
- EPSS 0.77%
- Published 23.07.2019 14:15:15
- Last modified 21.11.2024 04:21:39
Due to an error while parsing page content, it is possible for properly sanitized user input to be misinterpreted and lead to XSS hazards on web sites in certain circumstances. This vulnerability affects Firefox ESR < 60.8, Firefox < 68, and Thunderb...
CVE-2019-11716
- EPSS 0.58%
- Published 23.07.2019 14:15:15
- Last modified 21.11.2024 04:21:39
Until explicitly accessed by script, window.globalThis is not enumerable and, as a result, is not visible to code such as Object.getOwnPropertyNames(window). Sites that deploy a sandboxing that depends on enumerating and freezing access to the window...
CVE-2019-11717
- EPSS 5.03%
- Published 23.07.2019 14:15:15
- Last modified 21.11.2024 04:21:39
A vulnerability exists where the caret ("^") character is improperly escaped constructing some URIs due to it being used as a separator, allowing for possible spoofing of origin attributes. This vulnerability affects Firefox ESR < 60.8, Firefox < 68,...
CVE-2019-11718
- EPSS 0.73%
- Published 23.07.2019 14:15:15
- Last modified 21.11.2024 04:21:39
Activity Stream can display content from sent from the Snippet Service website. This content is written to innerHTML on the Activity Stream page without sanitization, allowing for a potential access to other information available to the Activity Stre...
CVE-2019-11693
- EPSS 0.6%
- Published 23.07.2019 14:15:14
- Last modified 21.11.2024 04:21:36
The bufferdata function in WebGL is vulnerable to a buffer overflow with specific graphics drivers on Linux. This could result in malicious content freezing a tab or triggering a potentially exploitable crash. *Note: this issue only occurs on Linux. ...
CVE-2019-11694
- EPSS 0.4%
- Published 23.07.2019 14:15:14
- Last modified 21.11.2024 04:21:36
A vulnerability exists in the Windows sandbox where an uninitialized value in memory can be leaked to a renderer from a broker when making a call to access an otherwise unavailable file. This results in the potential leaking of information stored at ...
CVE-2019-11695
- EPSS 0.19%
- Published 23.07.2019 14:15:14
- Last modified 21.11.2024 04:21:36
A custom cursor defined by scripting on a site can position itself over the addressbar to spoof the actual cursor when it should not be allowed outside of the primary web content area. This could be used by a malicious site to trick users into clicki...
CVE-2019-11696
- EPSS 0.16%
- Published 23.07.2019 14:15:14
- Last modified 21.11.2024 04:21:36
Files with the .JNLP extension used for "Java web start" applications are not treated as executable content for download prompts even though they can be executed if Java is installed on the local system. This could allow users to mistakenly launch an...
CVE-2019-11697
- EPSS 0.2%
- Published 23.07.2019 14:15:14
- Last modified 21.11.2024 04:21:36
If the ALT and "a" keys are pressed when users receive an extension installation prompt, the extension will be installed without the install prompt delay that keeps the prompt visible in order for users to accept or decline the installation. A malici...