説明
Multiple vulnerabilities were found in Mozilla Thunderbird. Malicious users can exploit these vulnerabilities to bypass security restrictions, spoof user interface, cause denial of service, perform cross-site scripting attack, obtain sensitive information, execute arbitrary code.
Below is a complete list of vulnerabilities:
- Unspecified vulnerability can be exploited Fetch API to bypass security restrictions;
- Unspecified vulnerability in Thunderbird can be exploited via cross-origin protection to bypass security restrictions;
- Unspecified vulnerability in Thunderbird can be exploited to spoof user interface;
- Unspecified vulnerability in Thunderbird can be exploited via p256-ECDH public keys forming to cause denial of service;
- Unspecified vulnerability in Thunderbird can be exploited via parsing page content to perform cross-site scripting;
- A use-after-free vulnerability in Thunderbird can be exploited to cause denial of service;
- Out-of-bounds read vulnerability in Thunderbird can be exploited via importing a curve25519 private key to obtain sensitive information;
- Unspecified vulnerability in Thunderbird can be exploited via NPAPI plugins to perform cross-site scripting;
- Unspecified vulnerability in Thunderbird can be exploited via sandbox to bypass security restrictions;
- Multiple memory corruption vulnerabilities can be exploited to execute arbitrary code.
オリジナルアドバイザリー
エクスプロイテーション
Public exploits exist for this vulnerability.
関連製品
CVEリスト
- CVE-2019-9811 critical
- CVE-2019-11711 critical
- CVE-2019-11712 critical
- CVE-2019-11713 critical
- CVE-2019-11729 critical
- CVE-2019-11715 high
- CVE-2019-11717 high
- CVE-2019-11719 critical
- CVE-2019-11730 high
- CVE-2019-11709 critical
も参照してください
お住まいの地域に広がる脆弱性の統計をご覧ください statistics.securelist.com
この脆弱性についての記述に不正確な点がありますか? お知らせください!