Логотип exploitDog
bind:"CVE-2019-11730"
Консоль
Логотип exploitDog

exploitDog

bind:"CVE-2019-11730"

Количество 24

Количество 24

ubuntu логотип

CVE-2019-11730

больше 6 лет назад

A vulnerability exists where if a user opens a locally saved HTML file, this file can use file: URIs to access other files in the same directory or sub-directories if the names are known or guessed. The Fetch API can then be used to read the contents of any files stored in these directories and they may uploaded to a server. It was demonstrated that in combination with a popular Android messaging app, if a malicious HTML attachment is sent to a user and they opened that attachment in Firefox, due to that app's predictable pattern for locally-saved file names, it is possible to read attachments the victim received from other correspondents. This vulnerability affects Firefox ESR < 60.8, Firefox < 68, and Thunderbird < 60.8.

CVSS3: 6.5
EPSS: Средний
redhat логотип

CVE-2019-11730

больше 6 лет назад

A vulnerability exists where if a user opens a locally saved HTML file, this file can use file: URIs to access other files in the same directory or sub-directories if the names are known or guessed. The Fetch API can then be used to read the contents of any files stored in these directories and they may uploaded to a server. It was demonstrated that in combination with a popular Android messaging app, if a malicious HTML attachment is sent to a user and they opened that attachment in Firefox, due to that app's predictable pattern for locally-saved file names, it is possible to read attachments the victim received from other correspondents. This vulnerability affects Firefox ESR < 60.8, Firefox < 68, and Thunderbird < 60.8.

CVSS3: 6.1
EPSS: Средний
nvd логотип

CVE-2019-11730

больше 6 лет назад

A vulnerability exists where if a user opens a locally saved HTML file, this file can use file: URIs to access other files in the same directory or sub-directories if the names are known or guessed. The Fetch API can then be used to read the contents of any files stored in these directories and they may uploaded to a server. It was demonstrated that in combination with a popular Android messaging app, if a malicious HTML attachment is sent to a user and they opened that attachment in Firefox, due to that app's predictable pattern for locally-saved file names, it is possible to read attachments the victim received from other correspondents. This vulnerability affects Firefox ESR < 60.8, Firefox < 68, and Thunderbird < 60.8.

CVSS3: 6.5
EPSS: Средний
debian логотип

CVE-2019-11730

больше 6 лет назад

A vulnerability exists where if a user opens a locally saved HTML file ...

CVSS3: 6.5
EPSS: Средний
github логотип

GHSA-353x-8rf5-m26c

больше 3 лет назад

A vulnerability exists where if a user opens a locally saved HTML file, this file can use file: URIs to access other files in the same directory or sub-directories if the names are known or guessed. The Fetch API can then be used to read the contents of any files stored in these directories and they may uploaded to a server. It was demonstrated that in combination with a popular Android messaging app, if a malicious HTML attachment is sent to a user and they opened that attachment in Firefox, due to that app's predictable pattern for locally-saved file names, it is possible to read attachments the victim received from other correspondents. This vulnerability affects Firefox ESR < 60.8, Firefox < 68, and Thunderbird < 60.8.

CVSS3: 6.5
EPSS: Средний
fstec логотип

BDU:2020-00723

больше 6 лет назад

Уязвимость веб-браузеров Firefox, Firefox ESR и программы для работы с электронной почтой Thunderbird, связанная с отсутствием защиты служебных данных, позволяющая нарушителю получить несанкционированный доступ к конфиденциальным данным

CVSS3: 6.5
EPSS: Средний
oracle-oval логотип

ELSA-2019-1799

больше 6 лет назад

ELSA-2019-1799: thunderbird security and bug fix update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2019-1777

больше 6 лет назад

ELSA-2019-1777: thunderbird security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2019-1775

больше 6 лет назад

ELSA-2019-1775: thunderbird security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2019-1765

больше 6 лет назад

ELSA-2019-1765: firefox security update (CRITICAL)

EPSS: Низкий
oracle-oval логотип

ELSA-2019-1764

больше 6 лет назад

ELSA-2019-1764: firefox security update (CRITICAL)

EPSS: Низкий
oracle-oval логотип

ELSA-2019-1763

больше 6 лет назад

ELSA-2019-1763: firefox security update (CRITICAL)

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2019:1813-1

больше 6 лет назад

Security update for MozillaThunderbird

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2019:1811-1

больше 6 лет назад

Security update for MozillaFirefox

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2019:1782-1

больше 6 лет назад

Security update for MozillaFirefox

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2019:1960-1

больше 6 лет назад

Security update for MozillaThunderbird

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2019:1869-1

больше 6 лет назад

Security update for MozillaFirefox

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2019:1861-1

больше 6 лет назад

Security update for MozillaFirefox

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2019:14124-1

больше 6 лет назад

Security update for MozillaFirefox

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2019:2249-1

больше 6 лет назад

Security update for MozillaThunderbird

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2019-11730

A vulnerability exists where if a user opens a locally saved HTML file, this file can use file: URIs to access other files in the same directory or sub-directories if the names are known or guessed. The Fetch API can then be used to read the contents of any files stored in these directories and they may uploaded to a server. It was demonstrated that in combination with a popular Android messaging app, if a malicious HTML attachment is sent to a user and they opened that attachment in Firefox, due to that app's predictable pattern for locally-saved file names, it is possible to read attachments the victim received from other correspondents. This vulnerability affects Firefox ESR < 60.8, Firefox < 68, and Thunderbird < 60.8.

CVSS3: 6.5
20%
Средний
больше 6 лет назад
redhat логотип
CVE-2019-11730

A vulnerability exists where if a user opens a locally saved HTML file, this file can use file: URIs to access other files in the same directory or sub-directories if the names are known or guessed. The Fetch API can then be used to read the contents of any files stored in these directories and they may uploaded to a server. It was demonstrated that in combination with a popular Android messaging app, if a malicious HTML attachment is sent to a user and they opened that attachment in Firefox, due to that app's predictable pattern for locally-saved file names, it is possible to read attachments the victim received from other correspondents. This vulnerability affects Firefox ESR < 60.8, Firefox < 68, and Thunderbird < 60.8.

CVSS3: 6.1
20%
Средний
больше 6 лет назад
nvd логотип
CVE-2019-11730

A vulnerability exists where if a user opens a locally saved HTML file, this file can use file: URIs to access other files in the same directory or sub-directories if the names are known or guessed. The Fetch API can then be used to read the contents of any files stored in these directories and they may uploaded to a server. It was demonstrated that in combination with a popular Android messaging app, if a malicious HTML attachment is sent to a user and they opened that attachment in Firefox, due to that app's predictable pattern for locally-saved file names, it is possible to read attachments the victim received from other correspondents. This vulnerability affects Firefox ESR < 60.8, Firefox < 68, and Thunderbird < 60.8.

CVSS3: 6.5
20%
Средний
больше 6 лет назад
debian логотип
CVE-2019-11730

A vulnerability exists where if a user opens a locally saved HTML file ...

CVSS3: 6.5
20%
Средний
больше 6 лет назад
github логотип
GHSA-353x-8rf5-m26c

A vulnerability exists where if a user opens a locally saved HTML file, this file can use file: URIs to access other files in the same directory or sub-directories if the names are known or guessed. The Fetch API can then be used to read the contents of any files stored in these directories and they may uploaded to a server. It was demonstrated that in combination with a popular Android messaging app, if a malicious HTML attachment is sent to a user and they opened that attachment in Firefox, due to that app's predictable pattern for locally-saved file names, it is possible to read attachments the victim received from other correspondents. This vulnerability affects Firefox ESR < 60.8, Firefox < 68, and Thunderbird < 60.8.

CVSS3: 6.5
20%
Средний
больше 3 лет назад
fstec логотип
BDU:2020-00723

Уязвимость веб-браузеров Firefox, Firefox ESR и программы для работы с электронной почтой Thunderbird, связанная с отсутствием защиты служебных данных, позволяющая нарушителю получить несанкционированный доступ к конфиденциальным данным

CVSS3: 6.5
20%
Средний
больше 6 лет назад
oracle-oval логотип
ELSA-2019-1799

ELSA-2019-1799: thunderbird security and bug fix update (IMPORTANT)

больше 6 лет назад
oracle-oval логотип
ELSA-2019-1777

ELSA-2019-1777: thunderbird security update (IMPORTANT)

больше 6 лет назад
oracle-oval логотип
ELSA-2019-1775

ELSA-2019-1775: thunderbird security update (IMPORTANT)

больше 6 лет назад
oracle-oval логотип
ELSA-2019-1765

ELSA-2019-1765: firefox security update (CRITICAL)

больше 6 лет назад
oracle-oval логотип
ELSA-2019-1764

ELSA-2019-1764: firefox security update (CRITICAL)

больше 6 лет назад
oracle-oval логотип
ELSA-2019-1763

ELSA-2019-1763: firefox security update (CRITICAL)

больше 6 лет назад
suse-cvrf логотип
openSUSE-SU-2019:1813-1

Security update for MozillaThunderbird

больше 6 лет назад
suse-cvrf логотип
openSUSE-SU-2019:1811-1

Security update for MozillaFirefox

больше 6 лет назад
suse-cvrf логотип
openSUSE-SU-2019:1782-1

Security update for MozillaFirefox

больше 6 лет назад
suse-cvrf логотип
SUSE-SU-2019:1960-1

Security update for MozillaThunderbird

больше 6 лет назад
suse-cvrf логотип
SUSE-SU-2019:1869-1

Security update for MozillaFirefox

больше 6 лет назад
suse-cvrf логотип
SUSE-SU-2019:1861-1

Security update for MozillaFirefox

больше 6 лет назад
suse-cvrf логотип
SUSE-SU-2019:14124-1

Security update for MozillaFirefox

больше 6 лет назад
suse-cvrf логотип
openSUSE-SU-2019:2249-1

Security update for MozillaThunderbird

больше 6 лет назад

Уязвимостей на страницу