KLA11546
Multiple vulnerabilities in Mozilla Firefox

Updated: 06/03/2020
Detect date
?
09/03/2019
Severity
?
Critical
Description

Multiple vulnerabilities were found in Mozilla Firefox. Malicious users can exploit these vulnerabilities to execute arbitrary code, cause denial of service, perform cross-site scripting attack, bypass security restrictions, gain privileges, obtain sensitive information.

Below is a complete list of vulnerabilities:

  1. A vulnerability can be exploited remotely to execute arbitrary code;
  2. Multiple use-after-free vulnerabilities can be exploited remotely to cause denial of service;
  3. A vulnerability can be exploited remotely to perform cross-site scripting attacks;
  4. A type confusion vulnerability can be exploited to cause denial of service;
  5. A sandbox escape vulnerability can be exploited to bypass security restrictions;
  6. A same-origin policy violation vulnerability can be exploited to bypass security restrictions;
  7. Multiple race condition vulnerabilities in Mozilla Maintenance Service can be exploited to gain privileges;
  8. Multiple memory corruption vulnerabilities can be exploited to execute arbitrary code;
  9. A vulnerability in WebRTC can be exploited to bypass security restrictions;
  10. An out-of-bounds read vulnerability in Skia can be exploited to obtain sensitive information;
  11. A cross-origin access vulnerability can be exploited to bypass security restrictions;
Affected products

Mozilla Firefox earlier than 69

Solution

Update to the latest version
Download Mozilla Firefox

Original advisories

mfsa2019-25

Impacts
?
ACE 
[?]

OSI 
[?]

DoS 
[?]

SB 
[?]

PE 
[?]

XSS/CSS 
[?]
Related products
Mozilla Firefox
CVE-IDS
?
CVE-2019-117516.8High
CVE-2019-117529.3Critical
CVE-2019-117357.5Critical
CVE-2019-117466.8High
CVE-2019-98125.8High
CVE-2019-117504.3Warning
CVE-2019-117424.3Warning
CVE-2019-117386.8High
CVE-2019-117494.3Warning
CVE-2019-117534.6Warning
CVE-2019-117364.4Warning
CVE-2019-117484.3Warning
CVE-2019-117407.5Critical
CVE-2019-117474.3Warning
CVE-2019-117444.3Warning
CVE-2019-117434.3Warning
CVE-2019-117347.5Critical
CVE-2019-117414.3Warning
CVE-2019-117375.0Critical
CVE-2019-58495.8High
CVE-2019-117586.8High
Find out the statistics of the vulnerabilities spreading in your region