Vulnerabilities > Mozilla > Firefox > Medium

DATE CVE VULNERABILITY TITLE RISK
2019-07-23 CVE-2019-11700 Missing Authorization vulnerability in Mozilla Firefox
A hyperlink using the res: protocol can be used to open local files at a known location in Internet Explorer if a user approves execution when prompted.
network
low complexity
mozilla CWE-862
6.5
2019-07-23 CVE-2019-11699 Unspecified vulnerability in Mozilla Firefox
A malicious page can briefly cause the wrong name to be highlighted as the domain name in the addressbar during page navigations.
network
low complexity
mozilla
6.5
2019-07-23 CVE-2019-11698 Improper Input Validation vulnerability in Mozilla Firefox
If a crafted hyperlink is dragged and dropped to the bookmark bar or sidebar and the resulting bookmark is subsequently dragged and dropped into the web content area, an arbitrary query of a user's browser history can be run and transmitted to the content page via drop event data.
network
low complexity
mozilla CWE-20
5.3
2019-07-23 CVE-2019-11697 Improper Input Validation vulnerability in Mozilla Firefox
If the ALT and "a" keys are pressed when users receive an extension installation prompt, the extension will be installed without the install prompt delay that keeps the prompt visible in order for users to accept or decline the installation.
network
low complexity
mozilla CWE-20
6.5
2019-07-23 CVE-2019-11695 Unspecified vulnerability in Mozilla Firefox
A custom cursor defined by scripting on a site can position itself over the addressbar to spoof the actual cursor when it should not be allowed outside of the primary web content area.
network
low complexity
mozilla
4.3
2019-04-26 CVE-2019-9808 Origin Validation Error vulnerability in Mozilla Firefox
If WebRTC permission is requested from documents with data: or blob: URLs, the permission notifications do not properly display the originating domain.
network
low complexity
mozilla CWE-346
5.3
2019-04-26 CVE-2019-9807 Improper Input Validation vulnerability in Mozilla Firefox
When arbitrary text is sent over an FTP connection and a page reload is initiated, it is possible to create a modal alert message with this text as the content.
network
low complexity
mozilla CWE-20
4.3
2019-04-26 CVE-2019-9801 Improper Input Validation vulnerability in Mozilla Firefox
Firefox will accept any registered Program ID as an external protocol handler and offer to launch this local application when given a matching URL on Windows operating systems.
network
low complexity
mozilla CWE-20
5.3
2019-04-26 CVE-2019-9797 Origin Validation Error vulnerability in Mozilla Firefox
Cross-origin images can be read in violation of the same-origin policy by exporting an image after using createImageBitmap to read the image and then rendering the resulting bitmap image within a canvas element.
network
low complexity
mozilla CWE-346
5.3
2019-04-26 CVE-2019-9793 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Mozilla Firefox
A mechanism was discovered that removes some bounds checking for string, array, or typed array accesses if Spectre mitigations have been disabled.
network
high complexity
mozilla CWE-119
5.9