Vulnerabilities > Mozilla > Medium

DATE CVE VULNERABILITY TITLE RISK
2020-01-08 CVE-2019-17000 Cross-site Scripting vulnerability in Mozilla Firefox
An object tag with a data URI did not correctly inherit the document's Content Security Policy.
network
low complexity
mozilla CWE-79
6.1
2020-01-08 CVE-2019-11765 Incorrect Default Permissions vulnerability in Mozilla Firefox
A compromised content process could send a message to the parent process that would cause the 'Click to Play' permission prompt to be shown.
network
low complexity
mozilla CWE-276
6.5
2020-01-08 CVE-2019-11763 Cross-site Scripting vulnerability in multiple products
Failure to correctly handle null bytes when processing HTML entities resulted in Firefox incorrectly parsing these entities.
network
low complexity
mozilla canonical CWE-79
6.1
2020-01-08 CVE-2019-11762 Origin Validation Error vulnerability in multiple products
If two same-origin documents set document.domain differently to become cross-origin, it was possible for them to call arbitrary DOM methods/getters/setters on the now-cross-origin window.
network
low complexity
mozilla canonical CWE-346
6.1
2020-01-08 CVE-2019-11761 Missing Authorization vulnerability in multiple products
By using a form with a data URI it was possible to gain access to the privileged JSONView object that had been cloned into content.
network
low complexity
mozilla canonical CWE-862
5.4
2019-12-10 CVE-2013-1689 Improper Input Validation vulnerability in Mozilla Firefox
Mozilla Firefox 20.0a1 and earlier allows remote attackers to cause a denial of service (crash), related to event handling with frames.
network
low complexity
mozilla CWE-20
6.5
2019-09-27 CVE-2019-11754 Unspecified vulnerability in Mozilla Firefox
When the pointer lock is enabled by a website though requestPointerLock(), no user notification is given.
network
low complexity
mozilla
4.3
2019-09-27 CVE-2019-11750 Use of Uninitialized Resource vulnerability in Mozilla Firefox
A type confusion vulnerability exists in Spidermonkey, which results in a non-exploitable crash.
network
low complexity
mozilla CWE-908
6.5
2019-09-27 CVE-2019-11749 Unspecified vulnerability in Mozilla Firefox
A vulnerability exists in WebRTC where malicious web content can use probing techniques on the getUserMedia API using constraints to reveal device properties of cameras on the system without triggering a user prompt or notification.
network
low complexity
mozilla
4.3
2019-09-27 CVE-2019-11748 Improper Preservation of Permissions vulnerability in Mozilla Firefox
WebRTC in Firefox will honor persisted permissions given to sites for access to microphone and camera resources even when in a third-party context.
network
low complexity
mozilla CWE-281
6.5