|
222951
|
6.5 |
MEDIUM
Network
|
mozilla canonical debian
|
firefox ubuntu_linux debian_linux
|
After a HelloRetryRequest has been sent, the client may negotiate a lower protocol that TLS 1.3, resulting in an invalid state transition in the TLS State Machine. If the client gets into this state,…
|
CWE-287
Improper Authentication
|
CVE-2019-17023
|
2024-11-21 13:31 |
2020-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222952
|
5.3 |
MEDIUM
Network
|
mozilla opensuse
|
firefox firefox_esr leap
|
During the initialization of a new content process, a race condition occurs that can allow a content process to disclose heap addresses from the parent process. *Note: this issue only occurs on Windo…
|
CWE-362
Race Condition
|
CVE-2019-17021
|
2024-11-21 13:31 |
2020-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222953
|
6.5 |
MEDIUM
Network
|
mozilla canonical
|
firefox ubuntu_linux
|
If an XML file is served with a Content Security Policy and the XML file includes an XSL stylesheet, the Content Security Policy will not be applied to the contents of the XSL stylesheet. If the XSL …
|
CWE-611
XXE
|
CVE-2019-17020
|
2024-11-21 13:31 |
2020-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222954
|
8.8 |
HIGH
Network
|
mozilla canonical debian redhat opensuse
|
firefox firefox_esr ubuntu_linux debian_linux enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server enterprise_linux enterprise_linux_eus enterprise…
|
Mozilla developers reported memory safety bugs present in Firefox 71 and Firefox ESR 68.3. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these…
|
CWE-787
Out-of-bounds Write
|
CVE-2019-17024
|
2024-11-21 13:31 |
2020-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222955
|
6.1 |
MEDIUM
Network
|
mozilla canonical debian redhat
|
firefox firefox_esr ubuntu_linux debian_linux enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server enterprise_linux_server_aus enterprise_linux_server…
|
When pasting a <style> tag from the clipboard into a rich text editor, the CSS sanitizer does not escape < and > characters. Because the resulting string is pasted directly into the text …
|
CWE-79
Cross-site Scripting
|
CVE-2019-17022
|
2024-11-21 13:31 |
2020-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222956
|
8.8 |
HIGH
Network
|
mozilla
|
firefox
|
When Python was installed on Windows, a python file being served with the MIME type of text/plain could be executed by Python instead of being opened as a text file when the Open option was selected …
|
NVD-CWE-noinfo
|
CVE-2019-17019
|
2024-11-21 13:31 |
2020-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222957
|
5.3 |
MEDIUM
Network
|
mozilla
|
firefox
|
When in Private Browsing Mode on Windows 10, the Windows keyboard may retain word suggestions to improve the accuracy of the keyboard. This vulnerability affects Firefox < 72.
|
CWE-200
Information Exposure
|
CVE-2019-17018
|
2024-11-21 13:31 |
2020-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222958
|
8.8 |
HIGH
Network
|
mozilla canonical debian redhat
|
firefox firefox_esr ubuntu_linux debian_linux enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server enterprise_linux_server_aus enterprise_linux_server…
|
Due to a missing case handling object types, a type confusion vulnerability could occur, resulting in a crash. We presume that with enough effort that it could be exploited to run arbitrary code. Thi…
|
CWE-843
Type Confusion
|
CVE-2019-17017
|
2024-11-21 13:31 |
2020-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222959
|
6.1 |
MEDIUM
Network
|
mozilla debian canonical redhat
|
firefox firefox_esr debian_linux ubuntu_linux enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server enterprise_linux_server_aus enterprise_linux_server…
|
When pasting a <style> tag from the clipboard into a rich text editor, the CSS sanitizer incorrectly rewrites a @namespace rule. This could allow for injection into certain types of websites re…
|
CWE-79
Cross-site Scripting
|
CVE-2019-17016
|
2024-11-21 13:31 |
2020-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222960
|
8.8 |
HIGH
Network
|
mozilla
|
firefox firefox_esr
|
During the initialization of a new content process, a pointer offset can be manipulated leading to memory corruption and a potentially exploitable crash in the parent process. *Note: this issue only …
|
CWE-787
Out-of-bounds Write
|
CVE-2019-17015
|
2024-11-21 13:31 |
2020-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|