Search CVE reports


Toggle filters

1361 – 1370 of 1493 results


CVE-2019-11752

Medium priority

Some fixes available 26 of 34

It is possible to delete an IndexedDB key value and subsequently try to extract it during conversion. This results in a use-after-free and a potentially exploitable crash. This vulnerability affects Firefox < 69, Thunderbird <...

5 affected packages

firefox, mozjs38, mozjs52, mozjs60, thunderbird

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox — Fixed Fixed Fixed Fixed
mozjs38 — Not in release Not in release Not in release Ignored
mozjs52 — Not in release Not in release Ignored Ignored
mozjs60 — Not in release Not in release Not in release Not in release
thunderbird — Fixed Fixed Fixed Fixed
Show less packages

CVE-2019-11750

Medium priority

Some fixes available 13 of 21

A type confusion vulnerability exists in Spidermonkey, which results in a non-exploitable crash. This vulnerability affects Firefox < 69 and Firefox ESR < 68.1.

4 affected packages

firefox, mozjs38, mozjs52, mozjs60

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox — Fixed Fixed Fixed Fixed
mozjs38 — Not in release Not in release Not in release Ignored
mozjs52 — Not in release Not in release Ignored Ignored
mozjs60 — Not in release Not in release Not in release Not in release
Show less packages

CVE-2019-11749

Medium priority

Some fixes available 13 of 21

A vulnerability exists in WebRTC where malicious web content can use probing techniques on the getUserMedia API using constraints to reveal device properties of cameras on the system without triggering a user prompt or...

4 affected packages

firefox, mozjs38, mozjs52, mozjs60

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox — Fixed Fixed Fixed Fixed
mozjs38 — Not in release Not in release Not in release Ignored
mozjs52 — Not in release Not in release Ignored Ignored
mozjs60 — Not in release Not in release Not in release Not in release
Show less packages

CVE-2019-11748

Medium priority

Some fixes available 13 of 21

WebRTC in Firefox will honor persisted permissions given to sites for access to microphone and camera resources even when in a third-party context. In light of recent high profile vulnerabilities in other software, a decision was...

4 affected packages

firefox, mozjs38, mozjs52, mozjs60

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox — Fixed Fixed Fixed Fixed
mozjs38 — Not in release Not in release Not in release Ignored
mozjs52 — Not in release Not in release Ignored Ignored
mozjs60 — Not in release Not in release Not in release Not in release
Show less packages

CVE-2019-11747

Negligible priority

Some fixes available 13 of 21

The "Forget about this site" feature in the History pane is intended to remove all saved user data that indicates a user has visited a site. This includes removing any HTTP Strict Transport Security (HSTS) settings received from...

4 affected packages

firefox, mozjs38, mozjs52, mozjs60

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox — Fixed Fixed Fixed Fixed
mozjs38 — Not in release Not in release Not in release Ignored
mozjs52 — Not in release Not in release Ignored Ignored
mozjs60 — Not in release Not in release Not in release Not in release
Show less packages

CVE-2019-11746

Medium priority

Some fixes available 26 of 34

A use-after-free vulnerability can occur while manipulating video elements if the body is freed while still in use. This results in a potentially exploitable crash. This vulnerability affects Firefox < 69, Thunderbird < 68.1,...

5 affected packages

firefox, mozjs38, mozjs52, mozjs60, thunderbird

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox — Fixed Fixed Fixed Fixed
mozjs38 — Not in release Not in release Not in release Ignored
mozjs52 — Not in release Not in release Ignored Ignored
mozjs60 — Not in release Not in release Not in release Not in release
thunderbird — Fixed Fixed Fixed Fixed
Show less packages

CVE-2019-11744

Medium priority

Some fixes available 26 of 34

Some HTML elements, such as &lt;title&gt; and &lt;textarea&gt;, can contain literal angle brackets without treating them as markup. It is possible to pass a literal closing tag to .innerHTML on these elements, and...

5 affected packages

firefox, mozjs38, mozjs52, mozjs60, thunderbird

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox — Fixed Fixed Fixed Fixed
mozjs38 — Not in release Not in release Not in release Ignored
mozjs52 — Not in release Not in release Ignored Ignored
mozjs60 — Not in release Not in release Not in release Not in release
thunderbird — Fixed Fixed Fixed Fixed
Show less packages

CVE-2019-11743

Medium priority

Some fixes available 26 of 34

Navigation events were not fully adhering to the W3C's "Navigation-Timing Level 2" draft specification in some instances for the unload event, which restricts access to detailed timing attributes to only be same-origin....

5 affected packages

firefox, mozjs38, mozjs52, mozjs60, thunderbird

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox — Fixed Fixed Fixed Fixed
mozjs38 — Not in release Not in release Not in release Ignored
mozjs52 — Not in release Not in release Ignored Ignored
mozjs60 — Not in release Not in release Not in release Not in release
thunderbird — Fixed Fixed Fixed Fixed
Show less packages

CVE-2019-11742

Medium priority

Some fixes available 26 of 34

A same-origin policy violation occurs allowing the theft of cross-origin images through a combination of SVG filters and a &lt;canvas&gt; element due to an error in how same-origin policy is applied to cached image content. The...

5 affected packages

firefox, mozjs38, mozjs52, mozjs60, thunderbird

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox — Fixed Fixed Fixed Fixed
mozjs38 — Not in release Not in release Not in release Ignored
mozjs52 — Not in release Not in release Ignored Ignored
mozjs60 — Not in release Not in release Not in release Not in release
thunderbird — Fixed Fixed Fixed Fixed
Show less packages

CVE-2019-11741

Medium priority

Some fixes available 13 of 21

A compromised sandboxed content process can perform a Universal Cross-site Scripting (UXSS) attack on content from any site it can cause to be loaded in the same process. Because addons.mozilla.org and accounts.firefox.com have...

4 affected packages

firefox, mozjs38, mozjs52, mozjs60

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox — Fixed Fixed Fixed Fixed
mozjs38 — Not in release Not in release Not in release Ignored
mozjs52 — Not in release Not in release Ignored Ignored
mozjs60 — Not in release Not in release Not in release Not in release
Show less packages