Vulnerabilities > Mozilla > Firefox > 67.0.3

DATE CVE VULNERABILITY TITLE RISK
2019-09-27 CVE-2019-11738 If a Content Security Policy (CSP) directive is defined that uses a hash-based source that takes the empty string as input, execution of any javascript: URIs will be allowed.
network
mozilla opensuse
6.8
2019-09-27 CVE-2019-11737 Insufficient Verification of Data Authenticity vulnerability in Mozilla Firefox
If a wildcard ('*') is specified for the host in Content Security Policy (CSP) directives, any port or path restriction of the directive will be ignored, leading to CSP directives not being properly applied to content.
network
low complexity
mozilla CWE-345
5.0
2019-09-27 CVE-2019-11736 Race Condition vulnerability in Mozilla Firefox
The Mozilla Maintenance Service does not guard against files being hardlinked to another file in the updates directory, allowing for the replacement of local files, including the Maintenance Service executable, which is run with privileged access.
4.4
2019-09-27 CVE-2019-11735 Out-of-bounds Write vulnerability in multiple products
Mozilla developers and community members reported memory safety bugs present in Firefox 68 and Firefox ESR 68.
6.8
2019-09-27 CVE-2019-11734 Classic Buffer Overflow vulnerability in Mozilla Firefox
Mozilla developers and community members reported memory safety bugs present in Firefox 68.
network
low complexity
mozilla CWE-120
7.5
2019-09-27 CVE-2019-11733 Improper Authentication vulnerability in Mozilla Firefox and Firefox ESR
When a master password is set, it is required to be entered again before stored passwords can be accessed in the 'Saved Logins' dialog.
network
low complexity
mozilla CWE-287
5.0
2019-07-23 CVE-2019-9811 Injection vulnerability in multiple products
As part of a winning Pwn2Own entry, a researcher demonstrated a sandbox escape by installing a malicious language pack and then opening a browser feature that used the compromised translation.
network
high complexity
mozilla debian novell opensuse CWE-74
8.3
2019-07-23 CVE-2019-11730 A vulnerability exists where if a user opens a locally saved HTML file, this file can use file: URIs to access other files in the same directory or sub-directories if the names are known or guessed.
network
low complexity
mozilla debian opensuse suse
6.5
2019-07-23 CVE-2019-11729 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Mozilla Firefox, Firefox ESR and Thunderbird
Empty or malformed p256-ECDH public keys may trigger a segmentation fault due values being improperly sanitized before being copied into memory and used.
network
low complexity
mozilla CWE-119
5.0
2019-07-23 CVE-2019-11728 Exposure of Resource to Wrong Sphere vulnerability in multiple products
The HTTP Alternative Services header, Alt-Svc, can be used by a malicious site to scan all TCP ports of any host that the accessible to a user when web content is loaded.
network
low complexity
mozilla opensuse CWE-668
4.7