Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2019-11708

Опубликовано: 20 июн. 2019
Источник: redhat
CVSS3: 10
EPSS Средний

Описание

Insufficient vetting of parameters passed with the Prompt:Open IPC message between child and parent processes can result in the non-sandboxed parent process opening web content chosen by a compromised child process. When combined with additional vulnerabilities this could result in executing arbitrary code on the user's computer. This vulnerability affects Firefox ESR < 60.7.2, Firefox < 67.0.4, and Thunderbird < 60.7.2.

Отчет

In general, this flaw cannot be exploited through email in Thunderbird because scripting is disabled when reading mail.

Дополнительная информация

Статус:

Important
Дефект:
CWE-270
https://bugzilla.redhat.com/show_bug.cgi?id=1722673Mozilla: Sandbox escape using Prompt:Open

EPSS

Процентиль: 98%
0.62964
Средний

10 Critical

CVSS3

Связанные уязвимости

CVSS3: 10
ubuntu
почти 6 лет назад

Insufficient vetting of parameters passed with the Prompt:Open IPC message between child and parent processes can result in the non-sandboxed parent process opening web content chosen by a compromised child process. When combined with additional vulnerabilities this could result in executing arbitrary code on the user's computer. This vulnerability affects Firefox ESR < 60.7.2, Firefox < 67.0.4, and Thunderbird < 60.7.2.

CVSS3: 10
nvd
почти 6 лет назад

Insufficient vetting of parameters passed with the Prompt:Open IPC message between child and parent processes can result in the non-sandboxed parent process opening web content chosen by a compromised child process. When combined with additional vulnerabilities this could result in executing arbitrary code on the user's computer. This vulnerability affects Firefox ESR < 60.7.2, Firefox < 67.0.4, and Thunderbird < 60.7.2.

CVSS3: 10
debian
почти 6 лет назад

Insufficient vetting of parameters passed with the Prompt:Open IPC mes ...

suse-cvrf
около 6 лет назад

Security update for MozillaFirefox

suse-cvrf
около 6 лет назад

Security update for MozillaFirefox

EPSS

Процентиль: 98%
0.62964
Средний

10 Critical

CVSS3

Уязвимость CVE-2019-11708