CVE-2019-9817
- EPSS 0.19%
- Veröffentlicht 23.07.2019 14:15:17
- Zuletzt bearbeitet 21.11.2024 04:52:22
Images from a different domain can be read using a canvas object in some circumstances. This could be used to steal image data from a different site in violation of same-origin policy. This vulnerability affects Thunderbird < 60.7, Firefox < 67, and ...
CVE-2019-9818
- EPSS 0.34%
- Veröffentlicht 23.07.2019 14:15:17
- Zuletzt bearbeitet 21.11.2024 04:52:22
A race condition is present in the crash generation server used to generate data for the crash reporter. This issue can lead to a use-after-free in the main process, resulting in a potentially exploitable crash and a sandbox escape. *Note: this vulne...
CVE-2019-9819
- EPSS 0.55%
- Veröffentlicht 23.07.2019 14:15:17
- Zuletzt bearbeitet 21.11.2024 04:52:22
A vulnerability where a JavaScript compartment mismatch can occur while working with the fetch API, resulting in a potentially exploitable crash. This vulnerability affects Thunderbird < 60.7, Firefox < 67, and Firefox ESR < 60.7.
CVE-2019-9820
- EPSS 0.55%
- Veröffentlicht 23.07.2019 14:15:17
- Zuletzt bearbeitet 21.11.2024 04:52:22
A use-after-free vulnerability can occur in the chrome event handler when it is freed while still in use. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 60.7, Firefox < 67, and Firefox ESR < 60.7.
CVE-2019-9821
- EPSS 0.42%
- Veröffentlicht 23.07.2019 14:15:17
- Zuletzt bearbeitet 21.11.2024 04:52:22
A use-after-free vulnerability can occur in AssertWorkerThread due to a race condition with shared workers. This results in a potentially exploitable crash. This vulnerability affects Firefox < 67.
CVE-2019-11719
- EPSS 0.45%
- Veröffentlicht 23.07.2019 14:15:16
- Zuletzt bearbeitet 25.11.2025 17:50:16
When importing a curve25519 private key in PKCS#8format with leading 0x00 bytes, it is possible to trigger an out-of-bounds read in the Network Security Services (NSS) library. This could lead to information disclosure. This vulnerability affects Fir...
CVE-2019-11720
- EPSS 0.74%
- Veröffentlicht 23.07.2019 14:15:16
- Zuletzt bearbeitet 21.11.2024 04:21:39
Some unicode characters are incorrectly treated as whitespace during the parsing of web content instead of triggering parsing errors. This allows malicious code to then be processed, evading cross-site scripting (XSS) filtering. This vulnerability af...
CVE-2019-11721
- EPSS 0.57%
- Veröffentlicht 23.07.2019 14:15:16
- Zuletzt bearbeitet 21.11.2024 04:21:39
The unicode latin 'kra' character can be used to spoof a standard 'k' character in the addressbar. This allows for domain spoofing attacks as do not display as punycode text, allowing for user confusion. This vulnerability affects Firefox < 68.
CVE-2019-11723
- EPSS 0.31%
- Veröffentlicht 23.07.2019 14:15:16
- Zuletzt bearbeitet 21.11.2024 04:21:39
A vulnerability exists during the installation of add-ons where the initial fetch ignored the origin attributes of the browsing context. This could leak cookies in private browsing mode or across different "containers" for people who use the Firefox ...
CVE-2019-11724
- EPSS 0.41%
- Veröffentlicht 23.07.2019 14:15:16
- Zuletzt bearbeitet 21.11.2024 04:21:40
Application permissions give additional remote troubleshooting permission to the site input.mozilla.org, which has been retired and now redirects to another site. This additional permission is unnecessary and is a potential vector for malicious attac...