|
210861
|
5.3 |
MEDIUM
Network
|
mozilla
|
firefox
|
Cross-origin images can be read in violation of the same-origin policy by exporting an image after using createImageBitmap to read the image and then rendering the resulting bitmap image within a can…
|
CWE-346
Origin Validation Error
|
CVE-2019-9797
|
2024-11-21 13:52 |
2019-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210862
|
5.3 |
MEDIUM
Network
|
mozilla
|
firefox firefox_esr thunderbird
|
Firefox will accept any registered Program ID as an external protocol handler and offer to launch this local application when given a matching URL on Windows operating systems. This should only happe…
|
CWE-20
Improper Input Validation
|
CVE-2019-9801
|
2024-11-21 13:52 |
2019-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210863
|
9.8 |
CRITICAL
Network
|
mozilla
|
firefox firefox_esr thunderbird
|
A use-after-free vulnerability can occur when the SMIL animation controller incorrectly registers with the refresh driver twice when only a single registration is expected. When a registration is lat…
|
CWE-416
Use After Free
|
CVE-2019-9796
|
2024-11-21 13:52 |
2019-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210864
|
9.8 |
CRITICAL
Network
|
mozilla
|
firefox firefox_esr thunderbird
|
A vulnerability where type-confusion in the IonMonkey just-in-time (JIT) compiler could potentially be used by malicious JavaScript to trigger a potentially exploitable crash. This vulnerability affe…
|
CWE-617 CWE-843
Reachable Assertion Type Confusion
|
CVE-2019-9795
|
2024-11-21 13:52 |
2019-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210865
|
9.8 |
CRITICAL
Network
|
mozilla
|
firefox firefox_esr thunderbird
|
A vulnerability was discovered where specific command line arguments are not properly discarded during Firefox invocation as a shell handler for URLs. This could be used to retrieve and execute files…
|
CWE-88
Argument Injection
|
CVE-2019-9794
|
2024-11-21 13:52 |
2019-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210866
|
5.9 |
MEDIUM
Network
|
mozilla
|
firefox firefox_esr thunderbird
|
A mechanism was discovered that removes some bounds checking for string, array, or typed array accesses if Spectre mitigations have been disabled. This vulnerability could allow an attacker to create…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2019-9793
|
2024-11-21 13:52 |
2019-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210867
|
9.8 |
CRITICAL
Network
|
mozilla redhat
|
firefox firefox_esr thunderbird enterprise_linux enterprise_linux_eus enterprise_linux_server_tus enterprise_linux_server_aus
|
The IonMonkey just-in-time (JIT) compiler can leak an internal JS_OPTIMIZED_OUT magic value to the running script during a bailout. This magic value can then be used by JavaScript to achieve memory c…
|
CWE-787
Out-of-bounds Write
|
CVE-2019-9792
|
2024-11-21 13:52 |
2019-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210868
|
9.8 |
CRITICAL
Network
|
mozilla
|
thunderbird firefox firefox_esr
|
A use-after-free vulnerability can occur when a raw pointer to a DOM element on a page is obtained using JavaScript and the element is then removed while still in use. This results in a potentially e…
|
CWE-416
Use After Free
|
CVE-2019-9790
|
2024-11-21 13:52 |
2019-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210869
|
9.8 |
CRITICAL
Network
|
mozilla
|
firefox
|
Mozilla developers and community members reported memory safety bugs present in Firefox 65. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of…
|
CWE-787
Out-of-bounds Write
|
CVE-2019-9789
|
2024-11-21 13:52 |
2019-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210870
|
9.8 |
CRITICAL
Network
|
mozilla redhat
|
firefox firefox_esr thunderbird enterprise_linux enterprise_linux_eus enterprise_linux_server_tus enterprise_linux_server_aus
|
The type inference system allows the compilation of functions that can cause type confusions between arbitrary objects when compiled through the IonMonkey just-in-time (JIT) compiler and when the con…
|
CWE-843
Type Confusion
|
CVE-2019-9791
|
2024-11-21 13:52 |
2019-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|