CVE-2019-11702
- EPSS 0.38%
- Veröffentlicht 23.07.2019 14:15:14
- Zuletzt bearbeitet 21.11.2024 04:21:37
A hyperlink using protocols associated with Internet Explorer, such as IE.HTTP:, can be used to open local files at a known location with Internet Explorer if a user approves execution when prompted. *Note: this issue only occurs on Windows. Other op...
CVE-2019-11691
- EPSS 0.52%
- Veröffentlicht 23.07.2019 14:15:13
- Zuletzt bearbeitet 21.11.2024 04:21:36
A use-after-free vulnerability can occur when working with XMLHttpRequest (XHR) in an event loop, causing the XHR main thread to be called after it has been freed. This results in a potentially exploitable crash. This vulnerability affects Thunderbir...
CVE-2019-11692
- EPSS 0.52%
- Veröffentlicht 23.07.2019 14:15:13
- Zuletzt bearbeitet 25.11.2025 17:50:16
A use-after-free vulnerability can occur when listeners are removed from the event listener manager while still in use, resulting in a potentially exploitable crash. This vulnerability affects Thunderbird < 60.7, Firefox < 67, and Firefox ESR < 60.7.
CVE-2019-9810
- EPSS 69.41%
- Veröffentlicht 26.04.2019 17:29:04
- Zuletzt bearbeitet 25.11.2025 17:50:16
Incorrect alias information in IonMonkey JIT compiler for Array.prototype.slice method may lead to missing bounds check and a buffer overflow. This vulnerability affects Firefox < 66.0.1, Firefox ESR < 60.6.1, and Thunderbird < 60.6.1.
CVE-2019-9813
- EPSS 51.92%
- Veröffentlicht 26.04.2019 17:29:04
- Zuletzt bearbeitet 25.11.2025 17:50:16
Incorrect handling of __proto__ mutations may lead to type confusion in IonMonkey JIT code and can be leveraged for arbitrary memory read and write. This vulnerability affects Firefox < 66.0.1, Firefox ESR < 60.6.1, and Thunderbird < 60.6.1.
CVE-2019-9802
- EPSS 0.21%
- Veröffentlicht 26.04.2019 17:29:03
- Zuletzt bearbeitet 21.11.2024 04:52:20
If a Sandbox content process is compromised, it can initiate an FTP download which will then use a child process to render the downloaded data. The downloaded data can then be passed to the Chrome process with an arbitrary file length supplied by an ...
CVE-2019-9803
- EPSS 0.13%
- Veröffentlicht 26.04.2019 17:29:03
- Zuletzt bearbeitet 21.11.2024 04:52:20
The Upgrade-Insecure-Requests (UIR) specification states that if UIR is enabled through Content Security Policy (CSP), navigation to a same-origin URL must be upgraded to HTTPS. Firefox will incorrectly navigate to an HTTP URL rather than perform the...
CVE-2019-9804
- EPSS 1.15%
- Veröffentlicht 26.04.2019 17:29:03
- Zuletzt bearbeitet 21.11.2024 04:52:20
In Firefox Developer Tools it is possible that pasting the result of the 'Copy as cURL' command into a command shell on macOS will cause the execution of unintended additional bash script commands if the URL was maliciously crafted. This is the resul...
CVE-2019-9805
- EPSS 0.42%
- Veröffentlicht 26.04.2019 17:29:03
- Zuletzt bearbeitet 21.11.2024 04:52:20
A latent vulnerability exists in the Prio library where data may be read from uninitialized memory for some functions, leading to potential memory corruption. This vulnerability affects Firefox < 66.
CVE-2019-9806
- EPSS 0.34%
- Veröffentlicht 26.04.2019 17:29:03
- Zuletzt bearbeitet 21.11.2024 04:52:20
A vulnerability exists during authorization prompting for FTP transaction where successive modal prompts are displayed and cannot be immediately dismissed. This allows for a denial of service (DOS) attack. This vulnerability affects Firefox < 66.