Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2019-11696

Опубликовано: 23 июл. 2019
Источник: debian
EPSS Низкий

Описание

Files with the .JNLP extension used for "Java web start" applications are not treated as executable content for download prompts even though they can be executed if Java is installed on the local system. This could allow users to mistakenly launch an executable binary locally. This vulnerability affects Firefox < 67.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
firefoxfixed67.0-1experimentalpackage
firefoxfixed67.0-2package

Примечания

  • https://www.mozilla.org/en-US/security/advisories/mfsa2019-13/#CVE-2019-11696

EPSS

Процентиль: 38%
0.00158
Низкий

Связанные уязвимости

CVSS3: 7.8
ubuntu
почти 6 лет назад

Files with the .JNLP extension used for "Java web start" applications are not treated as executable content for download prompts even though they can be executed if Java is installed on the local system. This could allow users to mistakenly launch an executable binary locally. This vulnerability affects Firefox < 67.

CVSS3: 7.8
nvd
почти 6 лет назад

Files with the .JNLP extension used for "Java web start" applications are not treated as executable content for download prompts even though they can be executed if Java is installed on the local system. This could allow users to mistakenly launch an executable binary locally. This vulnerability affects Firefox < 67.

CVSS3: 7.8
github
около 3 лет назад

Files with the .JNLP extension used for "Java web start" applications are not treated as executable content for download prompts even though they can be executed if Java is installed on the local system. This could allow users to mistakenly launch an executable binary locally. This vulnerability affects Firefox < 67.

CVSS3: 8.8
fstec
почти 6 лет назад

Уязвимость браузера Firefox, связанная с ошибками обработки исполняемого контента для приложений с расширением .JNLP, позволяющая нарушителю получить доступ к конфиденциальным данным, нарушить их целостность, а также вызвать отказ в обслуживании

EPSS

Процентиль: 38%
0.00158
Низкий