7.5
CVSSv2

CVE-2019-9796

Published: 26/04/2019 Updated: 26/06/2019
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

It exists that Thunderbird allowed PAC files to specify that requests to localhost are sent through the proxy to another server. If proxy auto-detection is enabled, an attacker could potentially exploit this to conduct attacks on local services and tools. (CVE-2018-18506)

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

mozilla thunderbird

mozilla firefox

mozilla firefox esr

Vendor Advisories

Synopsis Critical: firefox security update Type/Severity Security Advisory: Critical Topic An update for firefox is now available for Red Hat Enterprise Linux 7Red Hat Product Security has rated this update as having a security impact of Critical A Common Vulnerability Scoring System (CVSS) base score, wh ...
Synopsis Critical: firefox security update Type/Severity Security Advisory: Critical Topic An update for firefox is now available for Red Hat Enterprise Linux 8Red Hat Product Security has rated this update as having a security impact of Critical A Common Vulnerability Scoring System (CVSS) base score, wh ...
Synopsis Important: thunderbird security update Type/Severity Security Advisory: Important Topic An update for thunderbird is now available for Red Hat Enterprise Linux 7Red Hat Product Security has rated this update as having a security impact of Important A Common Vulnerability Scoring System (CVSS) bas ...
Synopsis Important: thunderbird security update Type/Severity Security Advisory: Important Topic An update for thunderbird is now available for Red Hat Enterprise Linux 8Red Hat Product Security has rated this update as having a security impact of Important A Common Vulnerability Scoring System (CVSS) bas ...
Synopsis Critical: firefox security update Type/Severity Security Advisory: Critical Topic An update for firefox is now available for Red Hat Enterprise Linux 6Red Hat Product Security has rated this update as having a security impact of Critical A Common Vulnerability Scoring System (CVSS) base score, wh ...
Synopsis Important: thunderbird security update Type/Severity Security Advisory: Important Topic An update for thunderbird is now available for Red Hat Enterprise Linux 6Red Hat Product Security has rated this update as having a security impact of Important A Common Vulnerability Scoring System (CVSS) bas ...
Multiple security issues have been found in the Thunderbird mail client, which could lead to the execution of arbitrary code or denial of service For the stable distribution (stretch), these problems have been fixed in version 1:6061-1~deb9u1 We recommend that you upgrade your thunderbird packages For the detailed security status of thunderbir ...
Multiple security issues have been found in the Mozilla Firefox web browser, which could potentially result in the execution of arbitrary code For the stable distribution (stretch), these problems have been fixed in version 6060esr-1~deb9u1 We recommend that you upgrade your firefox-esr packages For the detailed security status of firefox-esr ...
Several security issues were fixed in Firefox ...
USN-3918-1 caused a regression in Firefox ...
Several security issues were fixed in Firefox ...
USN-3918-1 caused a regression in Firefox ...
Several security issues were fixed in Thunderbird ...
When proxy auto-detection is enabled, if a web server serves a Proxy Auto-Configuration (PAC) file or if a PAC file is loaded locally, this PAC file can specify that requests to the localhost are to be sent through the proxy to another server This behavior is disallowed by default when a proxy is manually configured, but when enabled could allow f ...
A use-after-free vulnerability can occur in Firefox before 660 when the SMIL animation controller incorrectly registers with the refresh driver twice when only a single registration is expected When a registration is later freed with the removal of the animation controller element, the refresh driver incorrectly leaves a dangling pointer to the d ...
Mozilla Foundation Security Advisory 2019-11 Security vulnerabilities fixed in Thunderbird 606 Announced March 19, 2019 Impact critical Products Thunderbird Fixed in Thunderbird 606 ...
Mozilla Foundation Security Advisory 2019-07 Security vulnerabilities fixed in Firefox 66 Announced March 19, 2019 Impact critical Products Firefox Fixed in Firefox 66 ...
Mozilla Foundation Security Advisory 2019-08 Security vulnerabilities fixed in Firefox ESR 606 Announced March 19, 2019 Impact critical Products Firefox ESR Fixed in Firefox ESR 606 ...