6.8
CVSSv2

CVE-2019-11696

Published: 23/07/2019 Updated: 28/07/2019
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Files with the .JNLP extension used for "Java web start" applications are not treated as executable content for download prompts even though they can be executed if Java is installed on the local system. This could allow users to mistakenly launch an executable binary locally. This vulnerability affects Firefox < 67.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

mozilla firefox

Vendor Advisories

USN-3991-2 caused a regression in Firefox ...
Firefox could be made to crash or run programs as your login if it opened a malicious website ...
USN-3991-1 caused a regression in Firefox ...
Mozilla Foundation Security Advisory 2019-13 Security vulnerabilities fixed in Firefox 67 Announced May 21, 2019 Impact critical Products Firefox Fixed in Firefox 67 ...
Severity Unknown Remote Unknown Type Unknown Description AVG-966 firefox 6605-1 670-1 Low Fixed ...