Search CVE reports


Toggle filters

1341 – 1350 of 1417 results


CVE-2019-11695

Medium priority

Some fixes available 14 of 24

A custom cursor defined by scripting on a site can position itself over the addressbar to spoof the actual cursor when it should not be allowed outside of the primary web content area. This could be used by a malicious site...

4 affected packages

firefox, mozjs38, mozjs52, mozjs60

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox — Fixed Fixed Fixed Fixed
mozjs38 — Not in release Not in release Not in release Ignored
mozjs52 — Not in release Not in release Ignored Ignored
mozjs60 — Not in release Not in release Not in release Not in release
Show less packages

CVE-2019-11693

Medium priority

Some fixes available 28 of 38

The bufferdata function in WebGL is vulnerable to a buffer overflow with specific graphics drivers on Linux. This could result in malicious content freezing a tab or triggering a potentially exploitable crash. *Note: this issue...

5 affected packages

firefox, mozjs38, mozjs52, mozjs60, thunderbird

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox — Fixed Fixed Fixed Fixed
mozjs38 — Not in release Not in release Not in release Ignored
mozjs52 — Not in release Not in release Ignored Ignored
mozjs60 — Not in release Not in release Not in release Not in release
thunderbird — Fixed Fixed Fixed Fixed
Show less packages

CVE-2019-11692

Medium priority

Some fixes available 28 of 38

A use-after-free vulnerability can occur when listeners are removed from the event listener manager while still in use, resulting in a potentially exploitable crash. This vulnerability affects Thunderbird < 60.7, Firefox < 67, and...

5 affected packages

firefox, mozjs38, mozjs52, mozjs60, thunderbird

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox — Fixed Fixed Fixed Fixed
mozjs38 — Not in release Not in release Not in release Ignored
mozjs52 — Not in release Not in release Ignored Ignored
mozjs60 — Not in release Not in release Not in release Not in release
thunderbird — Fixed Fixed Fixed Fixed
Show less packages

CVE-2019-11691

Medium priority

Some fixes available 28 of 38

A use-after-free vulnerability can occur when working with XMLHttpRequest (XHR) in an event loop, causing the XHR main thread to be called after it has been freed. This results in a potentially exploitable crash....

5 affected packages

firefox, mozjs38, mozjs52, mozjs60, thunderbird

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox — Fixed Fixed Fixed Fixed
mozjs38 — Not in release Not in release Not in release Ignored
mozjs52 — Not in release Not in release Ignored Ignored
mozjs60 — Not in release Not in release Not in release Not in release
thunderbird — Fixed Fixed Fixed Fixed
Show less packages

CVE-2019-9804

Negligible priority
Ignored

In Firefox Developer Tools it is possible that pasting the result of the 'Copy as cURL' command into a command shell on macOS will cause the execution of unintended additional bash script commands if the URL was maliciously...

4 affected packages

firefox, mozjs38, mozjs52, mozjs60

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox — Not affected Not affected Not in release Not affected
mozjs38 — Not in release Not in release Not in release Ignored
mozjs52 — Not in release Not in release Ignored Ignored
mozjs60 — Not in release Not in release Not in release Not in release
Show less packages

CVE-2019-9801

Negligible priority
Ignored

Firefox will accept any registered Program ID as an external protocol handler and offer to launch this local application when given a matching URL on Windows operating systems. This should only happen if the program has...

5 affected packages

firefox, mozjs38, mozjs52, mozjs60, thunderbird

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox — Not affected Not affected Not in release Not affected
mozjs38 — Not in release Not in release Not in release Ignored
mozjs52 — Not in release Not in release Ignored Ignored
mozjs60 — Not in release Not in release Not in release Not in release
thunderbird — Not affected Not affected Not in release Not affected
Show less packages

CVE-2019-9798

Negligible priority
Ignored

On Android systems, Firefox can load a library from APITRACE_LIB, which is writable by all users and applications. This could allow malicious third party applications to execute a man-in-the-middle attack if a malicious code was...

4 affected packages

firefox, mozjs38, mozjs52, mozjs60

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox — Not affected Not affected Not in release Not affected
mozjs38 — Not in release Not in release Not in release Ignored
mozjs52 — Not in release Not in release Ignored Ignored
mozjs60 — Not in release Not in release Not in release Not in release
Show less packages

CVE-2019-9794

Negligible priority
Ignored

A vulnerability was discovered where specific command line arguments are not properly discarded during Firefox invocation as a shell handler for URLs. This could be used to retrieve and execute files whose location is supplied...

5 affected packages

firefox, mozjs38, mozjs52, mozjs60, thunderbird

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox — Not affected Not affected Not in release Not affected
mozjs38 — Not in release Not in release Not in release Ignored
mozjs52 — Not in release Not in release Ignored Ignored
mozjs60 — Not in release Not in release Not in release Not in release
thunderbird — Not affected Not affected Not in release Not affected
Show less packages

CVE-2019-9813

Medium priority

Some fixes available 30 of 40

Incorrect handling of __proto__ mutations may lead to type confusion in IonMonkey JIT code and can be leveraged for arbitrary memory read and write. This vulnerability affects Firefox < 66.0.1, Firefox ESR < 60.6.1, and...

5 affected packages

firefox, mozjs38, mozjs52, mozjs60, thunderbird

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox — Fixed Fixed Fixed Fixed
mozjs38 — Not in release Not in release Not in release Ignored
mozjs52 — Not in release Not in release Ignored Ignored
mozjs60 — Not in release Not in release Not in release Not in release
thunderbird — Fixed Fixed Fixed Fixed
Show less packages

CVE-2019-9810

Medium priority

Some fixes available 30 of 40

Incorrect alias information in IonMonkey JIT compiler for Array.prototype.slice method may lead to missing bounds check and a buffer overflow. This vulnerability affects Firefox < 66.0.1, Firefox ESR < 60.6.1, and Thunderbird < 60.6.1.

5 affected packages

firefox, mozjs38, mozjs52, mozjs60, thunderbird

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox — Fixed Fixed Fixed Fixed
mozjs38 — Not in release Not in release Not in release Ignored
mozjs52 — Not in release Not in release Ignored Ignored
mozjs60 — Not in release Not in release Not in release Not in release
thunderbird — Fixed Fixed Fixed Fixed
Show less packages