Kaspersky ID:
KLA11524
Fecha de detección:
07/09/2019
Actualizado:
01/28/2026

Descripción

Multiple vulnerabilities were found in Mozilla Thunderbird. Malicious users can exploit these vulnerabilities to bypass security restrictions, spoof user interface, cause denial of service, perform cross-site scripting attack, obtain sensitive information, execute arbitrary code.

Below is a complete list of vulnerabilities:

  1. Unspecified vulnerability can be exploited Fetch API to bypass security restrictions;
  2. Unspecified vulnerability in Thunderbird can be exploited via cross-origin protection to bypass security restrictions;
  3. Unspecified vulnerability in Thunderbird can be exploited to spoof user interface;
  4. Unspecified vulnerability in Thunderbird can be exploited via p256-ECDH public keys forming to cause denial of service;
  5. Unspecified vulnerability in Thunderbird can be exploited via parsing page content to perform cross-site scripting;
  6. A use-after-free vulnerability in Thunderbird can be exploited to cause denial of service;
  7. Out-of-bounds read vulnerability in Thunderbird can be exploited via importing a curve25519 private key to obtain sensitive information;
  8. Unspecified vulnerability in Thunderbird can be exploited via NPAPI plugins to perform cross-site scripting;
  9. Unspecified vulnerability in Thunderbird can be exploited via sandbox to bypass security restrictions;
  10. Multiple memory corruption vulnerabilities can be exploited to execute arbitrary code.

Notas informativas originales

Explotación

Public exploits exist for this vulnerability.

Productos relacionados

Lista CVE

  • CVE-2019-9811
    critical
  • CVE-2019-11711
    critical
  • CVE-2019-11712
    critical
  • CVE-2019-11713
    critical
  • CVE-2019-11729
    critical
  • CVE-2019-11715
    high
  • CVE-2019-11717
    high
  • CVE-2019-11719
    critical
  • CVE-2019-11730
    high
  • CVE-2019-11709
    critical

Leer más

Conozca las estadísticas de las vulnerabilidades que se propagan en su región statistics.securelist.com

¿Has encontrado algún error en la descripción de esta vulnerabilidad? ¡Háznoslo saber!
Kaspersky Next:
ciberseguridad redefinida
Leer más
Nuevo Kaspersky
¡Su vida digital merece una protección completa!
Leer más
Do you want to save your changes?
Your message has been sent successfully.