Vulnerabilities > Mozilla > Firefox ESR > 68.0
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2019-09-27 | CVE-2019-11738 | If a Content Security Policy (CSP) directive is defined that uses a hash-based source that takes the empty string as input, execution of any javascript: URIs will be allowed. | 6.8 |
2019-09-27 | CVE-2019-11736 | Race Condition vulnerability in Mozilla Firefox The Mozilla Maintenance Service does not guard against files being hardlinked to another file in the updates directory, allowing for the replacement of local files, including the Maintenance Service executable, which is run with privileged access. | 4.4 |
2019-09-27 | CVE-2019-11735 | Out-of-bounds Write vulnerability in multiple products Mozilla developers and community members reported memory safety bugs present in Firefox 68 and Firefox ESR 68. | 6.8 |
2019-09-27 | CVE-2019-11733 | Improper Authentication vulnerability in Mozilla Firefox and Firefox ESR When a master password is set, it is required to be entered again before stored passwords can be accessed in the 'Saved Logins' dialog. | 5.0 |