CVE-2019-11751
- EPSS 0.6%
- Veröffentlicht 27.09.2019 18:15:13
- Zuletzt bearbeitet 21.11.2024 04:21:43
Logging-related command line parameters are not properly sanitized when Firefox is launched by another program, such as when a user clicks on malicious links in a chat application. This can be used to write a log file to an arbitrary location such as...
CVE-2019-11752
- EPSS 0.89%
- Veröffentlicht 27.09.2019 18:15:13
- Zuletzt bearbeitet 25.11.2025 17:50:16
It is possible to delete an IndexedDB key value and subsequently try to extract it during conversion. This results in a use-after-free and a potentially exploitable crash. This vulnerability affects Firefox < 69, Thunderbird < 68.1, Thunderbird < 60....
CVE-2019-11753
- EPSS 0.06%
- Veröffentlicht 27.09.2019 18:15:13
- Zuletzt bearbeitet 25.11.2025 17:50:16
The Firefox installer allows Firefox to be installed to a custom user writable location, leaving it unprotected from manipulation by unprivileged users or malware. If the Mozilla Maintenance Service is manipulated to update this unprotected location ...
CVE-2019-11754
- EPSS 0.19%
- Veröffentlicht 27.09.2019 18:15:13
- Zuletzt bearbeitet 21.11.2024 04:21:43
When the pointer lock is enabled by a website though requestPointerLock(), no user notification is given. This could allow a malicious website to hijack the mouse pointer and confuse users. This vulnerability affects Firefox < 69.0.1.
CVE-2019-11743
- EPSS 0.99%
- Veröffentlicht 27.09.2019 18:15:12
- Zuletzt bearbeitet 25.11.2025 17:50:16
Navigation events were not fully adhering to the W3C's "Navigation-Timing Level 2" draft specification in some instances for the unload event, which restricts access to detailed timing attributes to only be same-origin. This resulted in potential cro...
CVE-2019-11744
- EPSS 0.79%
- Veröffentlicht 27.09.2019 18:15:12
- Zuletzt bearbeitet 25.11.2025 17:50:16
Some HTML elements, such as <title> and <textarea>, can contain literal angle brackets without treating them as markup. It is possible to pass a literal closing tag to .innerHTML on these elements, and subsequent content after that will b...
CVE-2019-11746
- EPSS 0.65%
- Veröffentlicht 27.09.2019 18:15:12
- Zuletzt bearbeitet 25.11.2025 17:50:16
A use-after-free vulnerability can occur while manipulating video elements if the body is freed while still in use. This results in a potentially exploitable crash. This vulnerability affects Firefox < 69, Thunderbird < 68.1, Thunderbird < 60.9, Fire...
CVE-2019-11747
- EPSS 0.35%
- Veröffentlicht 27.09.2019 18:15:12
- Zuletzt bearbeitet 21.11.2024 04:21:42
The "Forget about this site" feature in the History pane is intended to remove all saved user data that indicates a user has visited a site. This includes removing any HTTP Strict Transport Security (HSTS) settings received from sites that use it. Du...
CVE-2019-11748
- EPSS 0.3%
- Veröffentlicht 27.09.2019 18:15:12
- Zuletzt bearbeitet 21.11.2024 04:21:42
WebRTC in Firefox will honor persisted permissions given to sites for access to microphone and camera resources even when in a third-party context. In light of recent high profile vulnerabilities in other software, a decision was made to no longer pe...
CVE-2019-11749
- EPSS 0.37%
- Veröffentlicht 27.09.2019 18:15:12
- Zuletzt bearbeitet 21.11.2024 04:21:42
A vulnerability exists in WebRTC where malicious web content can use probing techniques on the getUserMedia API using constraints to reveal device properties of cameras on the system without triggering a user prompt or notification. This allows for t...