|
222191
|
6.1 |
MEDIUM
Network
|
mozilla canonical debian redhat
|
firefox firefox_esr ubuntu_linux debian_linux enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server enterprise_linux_server_aus enterprise_linux_server…
|
When pasting a <style> tag from the clipboard into a rich text editor, the CSS sanitizer does not escape < and > characters. Because the resulting string is pasted directly into the text …
|
CWE-79
Cross-site Scripting
|
CVE-2019-17022
|
2024-11-21 13:31 |
2020-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222192
|
8.8 |
HIGH
Network
|
mozilla
|
firefox
|
When Python was installed on Windows, a python file being served with the MIME type of text/plain could be executed by Python instead of being opened as a text file when the Open option was selected …
|
NVD-CWE-noinfo
|
CVE-2019-17019
|
2024-11-21 13:31 |
2020-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222193
|
5.3 |
MEDIUM
Network
|
mozilla
|
firefox
|
When in Private Browsing Mode on Windows 10, the Windows keyboard may retain word suggestions to improve the accuracy of the keyboard. This vulnerability affects Firefox < 72.
|
CWE-200
Information Exposure
|
CVE-2019-17018
|
2024-11-21 13:31 |
2020-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222194
|
8.8 |
HIGH
Network
|
mozilla canonical debian redhat
|
firefox firefox_esr ubuntu_linux debian_linux enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server enterprise_linux_server_aus enterprise_linux_server…
|
Due to a missing case handling object types, a type confusion vulnerability could occur, resulting in a crash. We presume that with enough effort that it could be exploited to run arbitrary code. Thi…
|
CWE-843
Type Confusion
|
CVE-2019-17017
|
2024-11-21 13:31 |
2020-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222195
|
6.1 |
MEDIUM
Network
|
mozilla debian canonical redhat
|
firefox firefox_esr debian_linux ubuntu_linux enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server enterprise_linux_server_aus enterprise_linux_server…
|
When pasting a <style> tag from the clipboard into a rich text editor, the CSS sanitizer incorrectly rewrites a @namespace rule. This could allow for injection into certain types of websites re…
|
CWE-79
Cross-site Scripting
|
CVE-2019-17016
|
2024-11-21 13:31 |
2020-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222196
|
8.8 |
HIGH
Network
|
mozilla
|
firefox firefox_esr
|
During the initialization of a new content process, a pointer offset can be manipulated leading to memory corruption and a potentially exploitable crash in the parent process. *Note: this issue only …
|
CWE-787
Out-of-bounds Write
|
CVE-2019-17015
|
2024-11-21 13:31 |
2020-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222197
|
7.4 |
HIGH
Network
|
mozilla
|
firefox
|
If an image had not loaded correctly (such as when it is not actually an image), it could be dragged and dropped cross-domain, resulting in a cross-origin information leak. This vulnerability affects…
|
CWE-863
Incorrect Authorization
|
CVE-2019-17014
|
2024-11-21 13:31 |
2020-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222198
|
8.8 |
HIGH
Network
|
mozilla
|
firefox
|
Mozilla developers reported memory safety bugs present in Firefox 70. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been expl…
|
CWE-787 CWE-416
Out-of-bounds Write Use After Free
|
CVE-2019-17013
|
2024-11-21 13:31 |
2020-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222199
|
8.8 |
HIGH
Network
|
mozilla opensuse canonical
|
firefox firefox_esr thunderbird leap ubuntu_linux
|
Mozilla developers reported memory safety bugs present in Firefox 70 and Firefox ESR 68.2. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these…
|
CWE-787
Out-of-bounds Write
|
CVE-2019-17012
|
2024-11-21 13:31 |
2020-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222200
|
7.5 |
HIGH
Network
|
mozilla opensuse canonical
|
firefox firefox_esr thunderbird leap ubuntu_linux
|
Under certain conditions, when retrieving a document from a DocShell in the antitracking code, a race condition could cause a use-after-free condition and a potentially exploitable crash. This vulner…
|
CWE-362
Race Condition
|
CVE-2019-17011
|
2024-11-21 13:31 |
2020-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|