Vulnerabilities > Mozilla > Firefox ESR > Medium

DATE CVE VULNERABILITY TITLE RISK
2019-09-27 CVE-2019-11749 Unspecified vulnerability in Mozilla Firefox
A vulnerability exists in WebRTC where malicious web content can use probing techniques on the getUserMedia API using constraints to reveal device properties of cameras on the system without triggering a user prompt or notification.
network
low complexity
mozilla
4.3
2019-09-27 CVE-2019-11748 Improper Preservation of Permissions vulnerability in Mozilla Firefox
WebRTC in Firefox will honor persisted permissions given to sites for access to microphone and camera resources even when in a third-party context.
network
low complexity
mozilla CWE-281
6.5
2019-09-27 CVE-2019-11747 Improper Initialization vulnerability in Mozilla Firefox
The "Forget about this site" feature in the History pane is intended to remove all saved user data that indicates a user has visited a site.
network
low complexity
mozilla CWE-665
6.5
2019-09-27 CVE-2019-11744 Cross-site Scripting vulnerability in Mozilla Firefox
Some HTML elements, such as <title> and <textarea>, can contain literal angle brackets without treating them as markup.
network
low complexity
mozilla CWE-79
6.1
2019-09-27 CVE-2019-11742 Inclusion of Functionality from Untrusted Control Sphere vulnerability in Mozilla Firefox
A same-origin policy violation occurs allowing the theft of cross-origin images through a combination of SVG filters and a <canvas> element due to an error in how same-origin policy is applied to cached image content.
network
low complexity
mozilla CWE-829
6.5
2019-09-27 CVE-2019-11738 If a Content Security Policy (CSP) directive is defined that uses a hash-based source that takes the empty string as input, execution of any javascript: URIs will be allowed.
network
low complexity
mozilla opensuse
6.3
2019-07-23 CVE-2019-9817 Origin Validation Error vulnerability in Mozilla Thunderbird
Images from a different domain can be read using a canvas object in some circumstances.
network
low complexity
mozilla CWE-346
5.3
2019-07-23 CVE-2019-9816 Type Confusion vulnerability in Mozilla Thunderbird
A possible vulnerability exists where type confusion can occur when manipulating JavaScript objects in object groups, allowing for the bypassing of security checks within these groups.
network
high complexity
mozilla CWE-843
5.9
2019-07-23 CVE-2019-11730 A vulnerability exists where if a user opens a locally saved HTML file, this file can use file: URIs to access other files in the same directory or sub-directories if the names are known or guessed.
network
low complexity
mozilla debian opensuse suse
6.5
2019-07-23 CVE-2019-11717 Improper Encoding or Escaping of Output vulnerability in multiple products
A vulnerability exists where the caret ("^") character is improperly escaped constructing some URIs due to it being used as a separator, allowing for possible spoofing of origin attributes.
network
low complexity
mozilla debian novell opensuse CWE-116
5.3