Search CVE reports


Toggle filters

1421 – 1430 of 1493 results


CVE-2019-9804

Negligible priority
Ignored

In Firefox Developer Tools it is possible that pasting the result of the 'Copy as cURL' command into a command shell on macOS will cause the execution of unintended additional bash script commands if the URL was maliciously...

4 affected packages

firefox, mozjs38, mozjs52, mozjs60

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox — Not affected Not affected Not in release Not affected
mozjs38 — Not in release Not in release Not in release Ignored
mozjs52 — Not in release Not in release Ignored Ignored
mozjs60 — Not in release Not in release Not in release Not in release
Show less packages

CVE-2019-9801

Negligible priority
Ignored

Firefox will accept any registered Program ID as an external protocol handler and offer to launch this local application when given a matching URL on Windows operating systems. This should only happen if the program has...

5 affected packages

firefox, mozjs38, mozjs52, mozjs60, thunderbird

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox — Not affected Not affected Not in release Not affected
mozjs38 — Not in release Not in release Not in release Ignored
mozjs52 — Not in release Not in release Ignored Ignored
mozjs60 — Not in release Not in release Not in release Not in release
thunderbird — Not affected Not affected Not in release Not affected
Show less packages

CVE-2019-9798

Negligible priority
Ignored

On Android systems, Firefox can load a library from APITRACE_LIB, which is writable by all users and applications. This could allow malicious third party applications to execute a man-in-the-middle attack if a malicious code was...

4 affected packages

firefox, mozjs38, mozjs52, mozjs60

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox — Not affected Not affected Not in release Not affected
mozjs38 — Not in release Not in release Not in release Ignored
mozjs52 — Not in release Not in release Ignored Ignored
mozjs60 — Not in release Not in release Not in release Not in release
Show less packages

CVE-2019-9794

Negligible priority
Ignored

A vulnerability was discovered where specific command line arguments are not properly discarded during Firefox invocation as a shell handler for URLs. This could be used to retrieve and execute files whose location is supplied...

5 affected packages

firefox, mozjs38, mozjs52, mozjs60, thunderbird

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox — Not affected Not affected Not in release Not affected
mozjs38 — Not in release Not in release Not in release Ignored
mozjs52 — Not in release Not in release Ignored Ignored
mozjs60 — Not in release Not in release Not in release Not in release
thunderbird — Not affected Not affected Not in release Not affected
Show less packages

CVE-2019-9813

Medium priority

Some fixes available 30 of 40

Incorrect handling of __proto__ mutations may lead to type confusion in IonMonkey JIT code and can be leveraged for arbitrary memory read and write. This vulnerability affects Firefox < 66.0.1, Firefox ESR < 60.6.1, and...

5 affected packages

firefox, mozjs38, mozjs52, mozjs60, thunderbird

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox — Fixed Fixed Fixed Fixed
mozjs38 — Not in release Not in release Not in release Ignored
mozjs52 — Not in release Not in release Ignored Ignored
mozjs60 — Not in release Not in release Not in release Not in release
thunderbird — Fixed Fixed Fixed Fixed
Show less packages

CVE-2019-9810

Medium priority

Some fixes available 30 of 40

Incorrect alias information in IonMonkey JIT compiler for Array.prototype.slice method may lead to missing bounds check and a buffer overflow. This vulnerability affects Firefox < 66.0.1, Firefox ESR < 60.6.1, and Thunderbird < 60.6.1.

5 affected packages

firefox, mozjs38, mozjs52, mozjs60, thunderbird

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox — Fixed Fixed Fixed Fixed
mozjs38 — Not in release Not in release Not in release Ignored
mozjs52 — Not in release Not in release Ignored Ignored
mozjs60 — Not in release Not in release Not in release Not in release
thunderbird — Fixed Fixed Fixed Fixed
Show less packages

CVE-2019-9809

Low priority

Some fixes available 15 of 25

If the source for resources on a page is through an FTP connection, it is possible to trigger a series of modal alert messages for these resources through invalid credentials or locations. These messages cannot be immediately...

4 affected packages

firefox, mozjs38, mozjs52, mozjs60

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox — Fixed Fixed Fixed Fixed
mozjs38 — Not in release Not in release Not in release Ignored
mozjs52 — Not in release Not in release Ignored Ignored
mozjs60 — Not in release Not in release Not in release Not in release
Show less packages

CVE-2019-9808

Low priority

Some fixes available 15 of 25

If WebRTC permission is requested from documents with data: or blob: URLs, the permission notifications do not properly display the originating domain. The notification states "Unknown origin" as the requestee, leading to user...

4 affected packages

firefox, mozjs38, mozjs52, mozjs60

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox — Fixed Fixed Fixed Fixed
mozjs38 — Not in release Not in release Not in release Ignored
mozjs52 — Not in release Not in release Ignored Ignored
mozjs60 — Not in release Not in release Not in release Not in release
Show less packages

CVE-2019-9807

Low priority

Some fixes available 15 of 25

When arbitrary text is sent over an FTP connection and a page reload is initiated, it is possible to create a modal alert message with this text as the content. This could potentially be used for social engineering attacks. This...

4 affected packages

firefox, mozjs38, mozjs52, mozjs60

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox — Fixed Fixed Fixed Fixed
mozjs38 — Not in release Not in release Not in release Ignored
mozjs52 — Not in release Not in release Ignored Ignored
mozjs60 — Not in release Not in release Not in release Not in release
Show less packages

CVE-2019-9806

Low priority

Some fixes available 15 of 25

A vulnerability exists during authorization prompting for FTP transaction where successive modal prompts are displayed and cannot be immediately dismissed. This allows for a denial of service (DOS) attack. This vulnerability...

4 affected packages

firefox, mozjs38, mozjs52, mozjs60

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox — Fixed Fixed Fixed Fixed
mozjs38 — Not in release Not in release Not in release Ignored
mozjs52 — Not in release Not in release Ignored Ignored
mozjs60 — Not in release Not in release Not in release Not in release
Show less packages