Log

CVE-2019-11691 created at 25 Sep 2019 19:31:40
Severity
+ Critical
Remote
+ Remote
Type
+ Arbitrary code execution
Description
+ A use-after-free vulnerability can occur in Firefox before 67.0 and Thunderbird before 60.7.0, when working with XMLHttpRequest (XHR) in an event loop, causing the XHR main thread to be called after it has been freed. This results in a potentially exploitable crash.
References
+ https://www.mozilla.org/en-US/security/advisories/mfsa2019-13/#CVE-2019-11691
+ https://www.mozilla.org/en-US/security/advisories/mfsa2019-15/#CVE-2019-11691
+ https://bugzilla.mozilla.org/show_bug.cgi?id=1542465
Notes
CVE-2019-11692 created at 25 Sep 2019 19:31:40
Severity
+ Critical
Remote
+ Remote
Type
+ Arbitrary code execution
Description
+ A use-after-free vulnerability can occur in Firefox before 67.0 and Thunderbird before 60.7.0, when listeners are removed from the event listener manager while still in use, resulting in a potentially exploitable crash.
References
+ https://www.mozilla.org/en-US/security/advisories/mfsa2019-13/#CVE-2019-11692
+ https://www.mozilla.org/en-US/security/advisories/mfsa2019-15/#CVE-2019-11692
+ https://bugzilla.mozilla.org/show_bug.cgi?id=1544670
Notes
CVE-2019-11693 created at 25 Sep 2019 19:31:40
Severity
+ Critical
Remote
+ Remote
Type
+ Arbitrary code execution
Description
+ The bufferdata function in WebGL in Firefox before 67.0 and Thunderbird before 60.7.0 is vulnerable to a buffer overflow with specific graphics drivers on Linux. This could result in malicious content freezing a tab or triggering a potentially exploitable crash.
References
+ https://www.mozilla.org/en-US/security/advisories/mfsa2019-13/#CVE-2019-11693
+ https://www.mozilla.org/en-US/security/advisories/mfsa2019-15/#CVE-2019-11693
+ https://bugzilla.mozilla.org/show_bug.cgi?id=1532525
Notes
CVE-2019-11695 created at 25 Sep 2019 19:31:40
Severity
+ Medium
Remote
+ Remote
Type
+ Content spoofing
Description
+ In Firefox before 67.0, a custom cursor defined by scripting on a site can position itself over the addressbar to spoof the actual cursor when it should not be allowed outside of the primary web content area. This could be used by a malicious site to trick users into clicking on permission prompts, doorhanger notifications, or other buttons inadvertently if the location is spoofed over the user interface.
References
+ https://www.mozilla.org/en-US/security/advisories/mfsa2019-13/#CVE-2019-11695
+ https://bugzilla.mozilla.org/show_bug.cgi?id=1445844
Notes
CVE-2019-11696 created at 25 Sep 2019 19:31:40
Severity
+ Medium
Remote
+ Remote
Type
+ Content spoofing
Description
+ In Firefox before 67.0, files with the .JNLP extension used for "Java web start" applications are not treated as executable content for download prompts even though they can be executed if Java is installed on the local system. This could allow users to mistakenly launch an executable binary locally.
References
+ https://www.mozilla.org/en-US/security/advisories/mfsa2019-13/#CVE-2019-11696
+ https://bugzilla.mozilla.org/show_bug.cgi?id=1392955
Notes
CVE-2019-11697 created at 25 Sep 2019 19:31:40
Severity
+ Medium
Remote
+ Remote
Type
+ Access restriction bypass
Description
+ In Firefox before 67.0, if the ALT and "a" keys are pressed when users receive an extension installation prompt, the extension will be installed without the install prompt delay that keeps the prompt visible in order for users to accept or decline the installation. A malicious web page could use this with spoofing on the page to trick users into installing a malicious extension.
References
+ https://www.mozilla.org/en-US/security/advisories/mfsa2019-13/#CVE-2019-11697
+ https://bugzilla.mozilla.org/show_bug.cgi?id=1440079
Notes
CVE-2019-11698 created at 25 Sep 2019 19:31:40
Severity
+ Medium
Remote
+ Remote
Type
+ Information disclosure
Description
+ If a crafted hyperlink is dragged and dropped to the bookmark bar or sidebar in Firefox before 67.0 or Thunderbird before 60.7.0, and the resulting bookmark is subsequently dragged and dropped into the web content area, an arbitrary query of a user's browser history can be run and transmitted to the content page via drop event data. This allows for the theft of browser history by a malicious site.
References
+ https://www.mozilla.org/en-US/security/advisories/mfsa2019-13/#CVE-2019-11698
+ https://www.mozilla.org/en-US/security/advisories/mfsa2019-15/#CVE-2019-11698
+ https://bugzilla.mozilla.org/show_bug.cgi?id=1543191
Notes
CVE-2019-11699 created at 25 Sep 2019 19:31:40
Severity
+ Low
Remote
+ Remote
Type
+ Content spoofing
Description
+ A malicious page can briefly cause the wrong name to be highlighted as the domain name in the addressbar during page navigations in Firefox before 67.0. This could result in user confusion of which site is currently loaded for spoofing attacks.
References
+ https://www.mozilla.org/en-US/security/advisories/mfsa2019-13/#CVE-2019-11699
+ https://bugzilla.mozilla.org/show_bug.cgi?id=1528939
Notes
CVE-2019-11701 created at 25 Sep 2019 19:31:40
Severity
+ Low
Remote
+ Remote
Type
+ Cross-site scripting
Description
+ The default webcal: protocol handler in Firefox before 67.0 will load a web site vulnerable to cross-site scripting (XSS) attacks. This default was left in place as a legacy feature and has now been removed.
References
+ https://www.mozilla.org/en-US/security/advisories/mfsa2019-13/#CVE-2019-11701
+ https://bugzilla.mozilla.org/show_bug.cgi?id=1518627
Notes
CVE-2019-11703 created at 25 Sep 2019 19:31:40
Severity
+ High
Remote
+ Remote
Type
+ Arbitrary code execution
Description
+ A flaw in Thunderbird's implementation of iCal before 60.7.1 causes a heap buffer overflow in parser_get_next_char when processing certain email messages, resulting in a potentially exploitable crash.
References
+ https://www.mozilla.org/en-US/security/advisories/mfsa2019-17/#CVE-2019-11703
+ https://bugzilla.mozilla.org/show_bug.cgi?id=1553820
+ https://seclists.org/oss-sec/2019/q2/158
+ https://www.x41-dsec.de/lab/advisories/x41-2019-002-thunderbird/
Notes