Search CVE reports


Toggle filters

931 – 940 of 1005 results


CVE-2019-11692

Medium priority

Some fixes available 28 of 38

A use-after-free vulnerability can occur when listeners are removed from the event listener manager while still in use, resulting in a potentially exploitable crash. This vulnerability affects Thunderbird < 60.7, Firefox < 67, and...

5 affected packages

firefox, mozjs38, mozjs52, mozjs60, thunderbird

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox Fixed Fixed Fixed Fixed
mozjs38 Not in release Not in release Not in release Ignored
mozjs52 Not in release Not in release Ignored Ignored
mozjs60 Not in release Not in release Not in release Not in release
thunderbird Fixed Fixed Fixed Fixed
Show less packages

CVE-2019-11691

Medium priority

Some fixes available 28 of 38

A use-after-free vulnerability can occur when working with XMLHttpRequest (XHR) in an event loop, causing the XHR main thread to be called after it has been freed. This results in a potentially exploitable crash....

5 affected packages

mozjs60, mozjs52, firefox, mozjs38, thunderbird

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mozjs60 Not in release Not in release Not in release Not in release
mozjs52 Not in release Not in release Ignored Ignored
firefox Fixed Fixed Fixed Fixed
mozjs38 Not in release Not in release Not in release Ignored
thunderbird Fixed Fixed Fixed Fixed
Show less packages

CVE-2019-9804

Negligible priority
Ignored

In Firefox Developer Tools it is possible that pasting the result of the 'Copy as cURL' command into a command shell on macOS will cause the execution of unintended additional bash script commands if the URL was maliciously...

4 affected packages

mozjs52, firefox, mozjs38, mozjs60

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mozjs52 Not in release Not in release Ignored Ignored
firefox Not affected Not affected Not in release Not affected
mozjs38 Not in release Not in release Not in release Ignored
mozjs60 Not in release Not in release Not in release Not in release
Show less packages

CVE-2019-9801

Negligible priority
Ignored

Firefox will accept any registered Program ID as an external protocol handler and offer to launch this local application when given a matching URL on Windows operating systems. This should only happen if the program has...

5 affected packages

firefox, mozjs38, mozjs52, mozjs60, thunderbird

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox Not affected Not affected Not in release Not affected
mozjs38 Not in release Not in release Not in release Ignored
mozjs52 Not in release Not in release Ignored Ignored
mozjs60 Not in release Not in release Not in release Not in release
thunderbird Not affected Not affected Not in release Not affected
Show less packages

CVE-2019-9798

Negligible priority
Ignored

On Android systems, Firefox can load a library from APITRACE_LIB, which is writable by all users and applications. This could allow malicious third party applications to execute a man-in-the-middle attack if a malicious code was...

4 affected packages

mozjs52, mozjs60, firefox, mozjs38

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mozjs52 Not in release Not in release Ignored Ignored
mozjs60 Not in release Not in release Not in release Not in release
firefox Not affected Not affected Not in release Not affected
mozjs38 Not in release Not in release Not in release Ignored
Show less packages

CVE-2019-9794

Negligible priority
Ignored

A vulnerability was discovered where specific command line arguments are not properly discarded during Firefox invocation as a shell handler for URLs. This could be used to retrieve and execute files whose location is supplied...

5 affected packages

firefox, mozjs52, mozjs60, mozjs38, thunderbird

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox Not affected Not affected Not in release Not affected
mozjs52 Not in release Not in release Ignored Ignored
mozjs60 Not in release Not in release Not in release Not in release
mozjs38 Not in release Not in release Not in release Ignored
thunderbird Not affected Not affected Not in release Not affected
Show less packages

CVE-2019-9813

Medium priority

Some fixes available 30 of 40

Incorrect handling of __proto__ mutations may lead to type confusion in IonMonkey JIT code and can be leveraged for arbitrary memory read and write. This vulnerability affects Firefox < 66.0.1, Firefox ESR < 60.6.1, and...

5 affected packages

mozjs38, mozjs52, mozjs60, firefox, thunderbird

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mozjs38 Not in release Not in release Not in release Ignored
mozjs52 Not in release Not in release Ignored Ignored
mozjs60 Not in release Not in release Not in release Not in release
firefox Fixed Fixed Fixed Fixed
thunderbird Fixed Fixed Fixed Fixed
Show less packages

CVE-2019-9810

Medium priority

Some fixes available 30 of 40

Incorrect alias information in IonMonkey JIT compiler for Array.prototype.slice method may lead to missing bounds check and a buffer overflow. This vulnerability affects Firefox < 66.0.1, Firefox ESR < 60.6.1, and Thunderbird < 60.6.1.

5 affected packages

mozjs52, firefox, mozjs38, mozjs60, thunderbird

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mozjs52 Not in release Not in release Ignored Ignored
firefox Fixed Fixed Fixed Fixed
mozjs38 Not in release Not in release Not in release Ignored
mozjs60 Not in release Not in release Not in release Not in release
thunderbird Fixed Fixed Fixed Fixed
Show less packages

CVE-2019-9809

Low priority

Some fixes available 15 of 25

If the source for resources on a page is through an FTP connection, it is possible to trigger a series of modal alert messages for these resources through invalid credentials or locations. These messages cannot be immediately...

4 affected packages

mozjs52, mozjs60, firefox, mozjs38

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mozjs52 Not in release Not in release Ignored Ignored
mozjs60 Not in release Not in release Not in release Not in release
firefox Fixed Fixed Fixed Fixed
mozjs38 Not in release Not in release Not in release Ignored
Show less packages

CVE-2019-9808

Low priority

Some fixes available 15 of 25

If WebRTC permission is requested from documents with data: or blob: URLs, the permission notifications do not properly display the originating domain. The notification states "Unknown origin" as the requestee, leading to user...

4 affected packages

mozjs52, firefox, mozjs38, mozjs60

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mozjs52 Not in release Not in release Ignored Ignored
firefox Fixed Fixed Fixed Fixed
mozjs38 Not in release Not in release Not in release Ignored
mozjs60 Not in release Not in release Not in release Not in release
Show less packages