6.5
CVSSv3

CVE-2019-11730

Published: 23/07/2019 Updated: 31/01/2023
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 386
Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N

Vulnerability Summary

A sandbox escape exists in Thunderbird. If a user were tricked in to installing a malicious language pack, an attacker could exploit this to gain additional privileges. (CVE-2019-9811)

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

mozilla firefox

mozilla firefox esr

mozilla thunderbird

debian debian linux 8.0

opensuse leap 15.0

opensuse leap 15.1

suse package_hub -

Vendor Advisories

Synopsis Critical: firefox security update Type/Severity Security Advisory: Critical Topic An update for firefox is now available for Red Hat Enterprise Linux 8Red Hat Product Security has rated this update as having a security impact of Critical A Common Vulnerability Scoring System (CVSS) base score, wh ...
Synopsis Important: thunderbird security and bug fix update Type/Severity Security Advisory: Important Topic An update for thunderbird is now available for Red Hat Enterprise Linux 8Red Hat Product Security has rated this update as having a security impact of Important A Common Vulnerability Scoring Syste ...
Synopsis Critical: firefox security update Type/Severity Security Advisory: Critical Topic An update for firefox is now available for Red Hat Enterprise Linux 7Red Hat Product Security has rated this update as having a security impact of Critical A Common Vulnerability Scoring System (CVSS) base score, wh ...
Synopsis Important: thunderbird security update Type/Severity Security Advisory: Important Topic An update for thunderbird is now available for Red Hat Enterprise Linux 7Red Hat Product Security has rated this update as having a security impact of Important A Common Vulnerability Scoring System (CVSS) bas ...
Synopsis Critical: firefox security update Type/Severity Security Advisory: Critical Topic An update for firefox is now available for Red Hat Enterprise Linux 6Red Hat Product Security has rated this update as having a security impact of Critical A Common Vulnerability Scoring System (CVSS) base score, wh ...
Synopsis Important: thunderbird security update Type/Severity Security Advisory: Important Topic An update for thunderbird is now available for Red Hat Enterprise Linux 6Red Hat Product Security has rated this update as having a security impact of Important A Common Vulnerability Scoring System (CVSS) bas ...
Several security issues were fixed in Thunderbird ...
Firefox could be made to crash or run programs as your login if it opened a malicious website ...
USN-4054-1 caused some minor regressions in Firefox ...
Multiple security issues have been found in the Mozilla Firefox web browser, which could potentially result in the execution of arbitrary code, cross-site scripting, spoofing, information disclosure, denial of service or cross-site request forgery For the oldstable distribution (stretch), these problems have been fixed in version 6080esr-1~deb9u ...
Multiple security issues have been found in Thunderbird which could potentially result in the execution of arbitrary code, cross-site scripting, spoofing, information disclosure, denial of service or cross-site request forgery CVE-2019-11719 and CVE-2019-11729 are only addressed for stretch, in buster Thunderbird uses the system-wide copy of NSS ...
When an inner window is reused, it does not consider the use of documentdomain for cross-origin protections If pages on different subdomains ever cooperatively use documentdomain, then either page can abuse this to inject script into arbitrary pages on the other subdomain, even those that did not use documentdomain to relax their origin securit ...
A vulnerability exists in Firefox before 680 where if a user opens a locally saved HTML file, this file can use file: URIs to access other files in the same directory or sub-directories if the names are known or guessed The Fetch API can then be used to read the contents of any files stored in these directories and they may uploaded to a server ...
Mozilla Foundation Security Advisory 2019-21 Security vulnerabilities fixed in Firefox 68 Announced July 9, 2019 Impact critical Products Firefox Fixed in Firefox 68 ...
Mozilla Foundation Security Advisory 2019-28 Security vulnerabilities fixed in Thunderbird 68 Announced August 27, 2019 Impact critical Products Thunderbird Fixed in Thunderbird 68 ...
Mozilla Foundation Security Advisory 2019-22 Security vulnerabilities fixed in Firefox ESR 608 Announced July 9, 2019 Impact critical Products Firefox ESR Fixed in Firefox ESR 608 ...
Mozilla Foundation Security Advisory 2019-23 Security vulnerabilities fixed in Thunderbird 608 Announced July 9, 2019 Impact critical Products Thunderbird Fixed in Thunderbird 608 ...

Github Repositories

README Pre-empt The code in the HTML pages uses in-browser babel and the dev-build of React in the browser Why Babel? Babel allow the use of more advanced JavaScript feature by converting code written in ECMAScript2015+ into backwards-compatible JavaScript that the browser can understand and enables me to code React in JSX Why React? Developing in React helps me build a more m

Engine 2d test javascript from scratch

Warning : not start indexhtml without server, because CVE-2019-11730 not allow to load script locally To run local application : start a server ex : - with visual-studio and plugin live-server - wamp on Windows - or remote server apache or other

An IndexedDB exploration repository

IndexedDB This is a simple web application demonstrating the use of the IndexedDB web API in order to implement a to-do list application Links developermozillaorg/en-US/docs/Web/API/IndexedDB_API/Using_IndexedDB Shows the basic usage of the IndexedDB API developermozillaorg/en-US/docs/Web/API/IndexedDB_API/Browser_storage_limits_and_eviction_criteria Goes

p7m è uno script per la gestione dei file con firma digitale nel formato CADES

P7M p7m è un p7m viewer e uno script per la gestione dei file con firma digitale nel formato CADES Permette di: verificare e visualizzare la firma digitale, estrarre l'allegato e visualizzarlo (p7m viewer), scaricare il i certificati dei certificatori (CA dal CNIPA) ispezionare il contenuto del file (debug per esperti) estrarre l'allegato di una fattura el

Project for the Advanced Graphics course

advanced-graphics-project Project for the Advanced Graphical Algorithms course Tested under Firefox 740 (64-bit) Pre-requirements under Firefox Because of the changes according to CVE-2019-11730, under Firefox we have to change a flag to not threat the file:/// URI as unique origin by CORS Copy about:config in to the URL bar and set privacyfile_unique_origin=False

Presentations from Brandon Mitchell

Presentations from Brandon Mitchell These slides are made with RemarkJS or Revealjs and should be viewable in any browser For slides in Revealjs: You can press "S" to see the speaker notes view For slides in RemarkJS: You can press "P" to see presenter notes For the slides with a live terminal, use "W" and "E" to pause/play the re

Portfolio Work in Progress, backup in case something has gone horribly wrong

Readme Link to published portfolio website and Github Repository- To whom it concerns, Please find the live version of this portfolio located at hiremartinolsonnetlifyapp/ The github repository can be found at githubcom/MartinO55/MGOlsongithubio Description and Purpose of portfolio website Purpose To communicate and demonstrate my abilities to prospective e

a classroom exercise that uses the Firefox XSLT processor for an HTML preview

TEI Exercise A quick and dirty text encoding exercise for the literature classroom that uses the Firefox XSLT processor to generate an HTML preview Needed: Firefox browser: wwwmozillaorg/en-US/firefox/new/ Visual Studio Code text editor: codevisualstudiocom/download The Scholarly XML extension in Visual Studio Code: marketplacevisualstudiocom/ite