7.5
CVSSv2

CVE-2019-9794

Published: 26/04/2019 Updated: 21/07/2021
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

A vulnerability exists where specific command line arguments are not properly discarded during Firefox invocation as a shell handler for URLs. This could be used to retrieve and execute files whose location is supplied through these command line arguments if Firefox is configured as the default URI handler for a given URI scheme in third party applications and these applications insufficiently sanitize URL data. *Note: This issue only affects Windows operating systems. Other operating systems are unaffected.*. This vulnerability affects Thunderbird < 60.6, Firefox ESR < 60.6, and Firefox < 66.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

mozilla thunderbird

mozilla firefox_esr

mozilla firefox

Vendor Advisories

Mozilla Foundation Security Advisory 2019-11 Security vulnerabilities fixed in Thunderbird 606 Announced March 19, 2019 Impact critical Products Thunderbird Fixed in Thunderbird 606 ...
Mozilla Foundation Security Advisory 2019-07 Security vulnerabilities fixed in Firefox 66 Announced March 19, 2019 Impact critical Products Firefox Fixed in Firefox 66 ...
Mozilla Foundation Security Advisory 2019-08 Security vulnerabilities fixed in Firefox ESR 606 Announced March 19, 2019 Impact critical Products Firefox ESR Fixed in Firefox ESR 606 ...