CVE-2019-11718
- EPSS 0.61%
- Veröffentlicht 23.07.2019 14:15:15
- Zuletzt bearbeitet 21.11.2024 04:21:39
Activity Stream can display content from sent from the Snippet Service website. This content is written to innerHTML on the Activity Stream page without sanitization, allowing for a potential access to other information available to the Activity Stre...
CVE-2019-11693
- EPSS 0.6%
- Veröffentlicht 23.07.2019 14:15:14
- Zuletzt bearbeitet 25.11.2025 17:50:16
The bufferdata function in WebGL is vulnerable to a buffer overflow with specific graphics drivers on Linux. This could result in malicious content freezing a tab or triggering a potentially exploitable crash. *Note: this issue only occurs on Linux. ...
CVE-2019-11694
- EPSS 0.4%
- Veröffentlicht 23.07.2019 14:15:14
- Zuletzt bearbeitet 25.11.2025 17:50:16
A vulnerability exists in the Windows sandbox where an uninitialized value in memory can be leaked to a renderer from a broker when making a call to access an otherwise unavailable file. This results in the potential leaking of information stored at ...
CVE-2019-11695
- EPSS 0.19%
- Veröffentlicht 23.07.2019 14:15:14
- Zuletzt bearbeitet 21.11.2024 04:21:36
A custom cursor defined by scripting on a site can position itself over the addressbar to spoof the actual cursor when it should not be allowed outside of the primary web content area. This could be used by a malicious site to trick users into clicki...
CVE-2019-11696
- EPSS 0.16%
- Veröffentlicht 23.07.2019 14:15:14
- Zuletzt bearbeitet 21.11.2024 04:21:36
Files with the .JNLP extension used for "Java web start" applications are not treated as executable content for download prompts even though they can be executed if Java is installed on the local system. This could allow users to mistakenly launch an...
CVE-2019-11697
- EPSS 0.2%
- Veröffentlicht 23.07.2019 14:15:14
- Zuletzt bearbeitet 21.11.2024 04:21:36
If the ALT and "a" keys are pressed when users receive an extension installation prompt, the extension will be installed without the install prompt delay that keeps the prompt visible in order for users to accept or decline the installation. A malici...
CVE-2019-11698
- EPSS 0.38%
- Veröffentlicht 23.07.2019 14:15:14
- Zuletzt bearbeitet 25.11.2025 17:50:16
If a crafted hyperlink is dragged and dropped to the bookmark bar or sidebar and the resulting bookmark is subsequently dragged and dropped into the web content area, an arbitrary query of a user's browser history can be run and transmitted to the co...
CVE-2019-11699
- EPSS 0.2%
- Veröffentlicht 23.07.2019 14:15:14
- Zuletzt bearbeitet 21.11.2024 04:21:37
A malicious page can briefly cause the wrong name to be highlighted as the domain name in the addressbar during page navigations. This could result in user confusion of which site is currently loaded for spoofing attacks. This vulnerability affects F...
CVE-2019-11700
- EPSS 0.38%
- Veröffentlicht 23.07.2019 14:15:14
- Zuletzt bearbeitet 21.11.2024 04:21:37
A hyperlink using the res: protocol can be used to open local files at a known location in Internet Explorer if a user approves execution when prompted. *Note: this issue only occurs on Windows. Other operating systems are unaffected.*. This vulnerab...
CVE-2019-11701
- EPSS 0.24%
- Veröffentlicht 23.07.2019 14:15:14
- Zuletzt bearbeitet 21.11.2024 04:21:37
The default webcal: protocol handler will load a web site vulnerable to cross-site scripting (XSS) attacks. This default was left in place as a legacy feature and has now been removed. *Note: this issue only affects users with an account on the vulne...