Show filters
221 Total Results
Displaying 41-50 of 221
Sort by:
Attacker Value
Unknown
CVE-2019-11757
Disclosure Date: January 08, 2020 (last updated February 21, 2025)
When following the value's prototype chain, it was possible to retain a reference to a locale, delete it, and subsequently reference it. This resulted in a use-after-free and a potentially exploitable crash. This vulnerability affects Firefox < 70, Thunderbird < 68.2, and Firefox ESR < 68.2.
0
Attacker Value
Unknown
CVE-2019-11758
Disclosure Date: January 08, 2020 (last updated February 21, 2025)
Mozilla community member Philipp reported a memory safety bug present in Firefox 68 when 360 Total Security was installed. This bug showed evidence of memory corruption in the accessibility engine and we presume that with enough effort that it could be exploited to run arbitrary code. This vulnerability affects Firefox < 69, Thunderbird < 68.2, and Firefox ESR < 68.2.
0
Attacker Value
Unknown
CVE-2019-11763
Disclosure Date: January 08, 2020 (last updated February 21, 2025)
Failure to correctly handle null bytes when processing HTML entities resulted in Firefox incorrectly parsing these entities. This could have led to HTML comment text being treated as HTML which could have led to XSS in a web application under certain conditions. It could have also led to HTML entities being masked from filters - enabling the use of entities to mask the actual characters of interest from filters. This vulnerability affects Firefox < 70, Thunderbird < 68.2, and Firefox ESR < 68.2.
0
Attacker Value
Unknown
CVE-2019-11760
Disclosure Date: January 08, 2020 (last updated February 21, 2025)
A fixed-size stack buffer could overflow in nrappkit when doing WebRTC signaling. This resulted in a potentially exploitable crash in some instances. This vulnerability affects Firefox < 70, Thunderbird < 68.2, and Firefox ESR < 68.2.
0
Attacker Value
Unknown
CVE-2019-11740
Disclosure Date: September 27, 2019 (last updated November 27, 2024)
Mozilla developers and community members reported memory safety bugs present in Firefox 68, Firefox ESR 68, and Firefox 60.8. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firefox < 69, Thunderbird < 68.1, Thunderbird < 60.9, Firefox ESR < 60.9, and Firefox ESR < 68.1.
0
Attacker Value
Unknown
CVE-2019-11745
Disclosure Date: August 14, 2019 (last updated February 21, 2025)
When encrypting with a block cipher, if a call to NSC_EncryptUpdate was made with data smaller than the block size, a small out of bounds write could occur. This could have caused heap corruption and a potentially exploitable crash. This vulnerability affects Thunderbird < 68.3, Firefox ESR < 68.3, and Firefox < 71.
0
Attacker Value
Unknown
CVE-2019-11759
Disclosure Date: August 14, 2019 (last updated February 21, 2025)
An attacker could have caused 4 bytes of HMAC output to be written past the end of a buffer stored on the stack. This could be used by an attacker to execute arbitrary code or more likely lead to a crash. This vulnerability affects Firefox < 70, Thunderbird < 68.2, and Firefox ESR < 68.2.
0
Attacker Value
Unknown
CVE-2019-17025
Disclosure Date: March 11, 2019 (last updated February 21, 2025)
Mozilla developers reported memory safety bugs present in Firefox 71. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 72.
0
Attacker Value
Unknown
CVE-2018-12399
Disclosure Date: February 28, 2019 (last updated November 27, 2024)
When a new protocol handler is registered, the API accepts a title argument which can be used to mislead users about which domain is registering the new protocol. This may result in the user approving a protocol handler that they otherwise would not have. This vulnerability affects Firefox < 63.
0
Attacker Value
Unknown
CVE-2018-18495
Disclosure Date: February 28, 2019 (last updated November 27, 2024)
WebExtension content scripts can be loaded into about: pages in some circumstances, in violation of the permissions granted to extensions. This could allow an extension to interfere with the loading and usage of these pages and use capabilities that were intended to be restricted from extensions. This vulnerability affects Firefox < 64.
0