CVE-2019-11742
- EPSS 0.53%
- Veröffentlicht 27.09.2019 18:15:11
- Zuletzt bearbeitet 25.11.2025 17:50:16
A same-origin policy violation occurs allowing the theft of cross-origin images through a combination of SVG filters and a <canvas> element due to an error in how same-origin policy is applied to cached image content. The resulting same-origin ...
CVE-2019-9815
- EPSS 1%
- Veröffentlicht 23.07.2019 14:15:17
- Zuletzt bearbeitet 21.11.2024 04:52:21
If hyperthreading is not disabled, a timing attack vulnerability exists, similar to previous Spectre attacks. Apple has shipped macOS 10.14.5 with an option to disable hyperthreading in applications running untrusted code in a thread through a new sy...
CVE-2019-9816
- EPSS 37.84%
- Veröffentlicht 23.07.2019 14:15:17
- Zuletzt bearbeitet 21.11.2024 04:52:22
A possible vulnerability exists where type confusion can occur when manipulating JavaScript objects in object groups, allowing for the bypassing of security checks within these groups. *Note: this vulnerability has only been demonstrated with Unboxed...
CVE-2019-9817
- EPSS 0.19%
- Veröffentlicht 23.07.2019 14:15:17
- Zuletzt bearbeitet 21.11.2024 04:52:22
Images from a different domain can be read using a canvas object in some circumstances. This could be used to steal image data from a different site in violation of same-origin policy. This vulnerability affects Thunderbird < 60.7, Firefox < 67, and ...
CVE-2019-9818
- EPSS 0.34%
- Veröffentlicht 23.07.2019 14:15:17
- Zuletzt bearbeitet 21.11.2024 04:52:22
A race condition is present in the crash generation server used to generate data for the crash reporter. This issue can lead to a use-after-free in the main process, resulting in a potentially exploitable crash and a sandbox escape. *Note: this vulne...
CVE-2019-9819
- EPSS 0.54%
- Veröffentlicht 23.07.2019 14:15:17
- Zuletzt bearbeitet 21.11.2024 04:52:22
A vulnerability where a JavaScript compartment mismatch can occur while working with the fetch API, resulting in a potentially exploitable crash. This vulnerability affects Thunderbird < 60.7, Firefox < 67, and Firefox ESR < 60.7.
CVE-2019-9820
- EPSS 0.54%
- Veröffentlicht 23.07.2019 14:15:17
- Zuletzt bearbeitet 21.11.2024 04:52:22
A use-after-free vulnerability can occur in the chrome event handler when it is freed while still in use. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 60.7, Firefox < 67, and Firefox ESR < 60.7.
CVE-2019-9821
- EPSS 0.42%
- Veröffentlicht 23.07.2019 14:15:17
- Zuletzt bearbeitet 21.11.2024 04:52:22
A use-after-free vulnerability can occur in AssertWorkerThread due to a race condition with shared workers. This results in a potentially exploitable crash. This vulnerability affects Firefox < 67.
CVE-2019-11719
- EPSS 0.44%
- Veröffentlicht 23.07.2019 14:15:16
- Zuletzt bearbeitet 25.11.2025 17:50:16
When importing a curve25519 private key in PKCS#8format with leading 0x00 bytes, it is possible to trigger an out-of-bounds read in the Network Security Services (NSS) library. This could lead to information disclosure. This vulnerability affects Fir...
CVE-2019-11720
- EPSS 0.73%
- Veröffentlicht 23.07.2019 14:15:16
- Zuletzt bearbeitet 21.11.2024 04:21:39
Some unicode characters are incorrectly treated as whitespace during the parsing of web content instead of triggering parsing errors. This allows malicious code to then be processed, evading cross-site scripting (XSS) filtering. This vulnerability af...