4.3
CVSSv2

CVE-2019-11765

Published: 08/01/2020 Updated: 13/01/2020
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

A compromised content process could send a message to the parent process that would cause the 'Click to Play' permission prompt to be shown. However, due to lack of validation from the parent process, if the user accepted the permission request an attacker-controlled permission would be granted rather than the 'Click to Play' permission. This vulnerability affects Firefox < 70.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

mozilla firefox

Vendor Advisories

Firefox could be made to crash or run programs as your login if it opened a malicious website ...
Mozilla Foundation Security Advisory 2019-34 Security vulnerabilities fixed in - Firefox 70 Announced October 22, 2019 Impact critical Products Firefox Fixed in Firefox 70 ...
Severity Unknown Remote Unknown Type Unknown Description AVG-1055 firefox 6903-1 700-1 Unknown Fixed ...