|
212591
|
9.8 |
CRITICAL
Network
|
mozilla
|
thunderbird firefox_esr firefox
|
A vulnerability where a JavaScript compartment mismatch can occur while working with the fetch API, resulting in a potentially exploitable crash. This vulnerability affects Thunderbird < 60.7, Firefo…
|
CWE-843
Type Confusion
|
CVE-2019-9819
|
2024-11-21 13:52 |
2019-07-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212592
|
8.3 |
HIGH
Network
|
mozilla
|
firefox firefox_esr thunderbird
|
A race condition is present in the crash generation server used to generate data for the crash reporter. This issue can lead to a use-after-free in the main process, resulting in a potentially exploi…
|
CWE-362 CWE-416
Race Condition Use After Free
|
CVE-2019-9818
|
2024-11-21 13:52 |
2019-07-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212593
|
5.3 |
MEDIUM
Network
|
mozilla
|
thunderbird firefox_esr firefox
|
Images from a different domain can be read using a canvas object in some circumstances. This could be used to steal image data from a different site in violation of same-origin policy. This vulnerabi…
|
CWE-346
Origin Validation Error
|
CVE-2019-9817
|
2024-11-21 13:52 |
2019-07-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212594
|
5.9 |
MEDIUM
Network
|
mozilla
|
thunderbird firefox_esr firefox
|
A possible vulnerability exists where type confusion can occur when manipulating JavaScript objects in object groups, allowing for the bypassing of security checks within these groups. *Note: this vu…
|
CWE-843
Type Confusion
|
CVE-2019-9816
|
2024-11-21 13:52 |
2019-07-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212595
|
9.8 |
CRITICAL
Network
|
mozilla
|
firefox
|
Mozilla developers and community members reported memory safety bugs present in Firefox 66. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of…
|
CWE-787
Out-of-bounds Write
|
CVE-2019-9814
|
2024-11-21 13:52 |
2019-07-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212596
|
8.3 |
HIGH
Network
|
mozilla debian novell opensuse
|
firefox firefox_esr thunderbird debian_linux suse_package_hub_for_suse_linux_enterprise leap
|
As part of a winning Pwn2Own entry, a researcher demonstrated a sandbox escape by installing a malicious language pack and then opening a browser feature that used the compromised translation. This v…
|
CWE-74
Injection
|
CVE-2019-9811
|
2024-11-21 13:52 |
2019-07-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212597
|
9.8 |
CRITICAL
Network
|
mozilla
|
thunderbird firefox_esr firefox
|
Mozilla developers and community members reported memory safety bugs present in Firefox 66, Firefox ESR 60.6, and Thunderbird 60.6. Some of these bugs showed evidence of memory corruption and we pres…
|
CWE-787
Out-of-bounds Write
|
CVE-2019-9800
|
2024-11-21 13:52 |
2019-07-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212598
|
6.5 |
MEDIUM
Network
|
freedesktop debian fedoraproject redhat
|
poppler debian_linux fedora enterprise_linux enterprise_linux_eus enterprise_linux_server_tus enterprise_linux_server_aus
|
The JPXStream::init function in Poppler 0.78.0 and earlier doesn't check for negative values of stream length, leading to an Integer Overflow, thereby making it possible to allocate a large memory ch…
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2019-9959
|
2024-11-21 13:52 |
2019-07-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212599
|
8.1 |
HIGH
Network
|
mozilla
|
firefox firefox_esr thunderbird
|
If hyperthreading is not disabled, a timing attack vulnerability exists, similar to previous Spectre attacks. Apple has shipped macOS 10.14.5 with an option to disable hyperthreading in applications …
|
CWE-203
Information Exposure Through Discrepancy
|
CVE-2019-9815
|
2024-11-21 13:52 |
2019-07-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212600
|
4.3 |
MEDIUM
Network
|
libreoffice canonical fedoraproject debian opensuse
|
libreoffice ubuntu_linux fedora debian_linux leap
|
LibreOffice has a 'stealth mode' in which only documents from locations deemed 'trusted' are allowed to retrieve remote resources. This mode is not the default mode, but can be enabled by users who w…
|
NVD-CWE-noinfo
|
CVE-2019-9849
|
2024-11-21 13:52 |
2019-07-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|