Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2019-11708
Description:Insufficient vetting of parameters passed with the Prompt:Open IPC message between child and parent processes can result in the non- sandboxed parent process opening web content chosen by a compromised child process. When combined with additional vulnerabilities this could result in executing arbitrary code on the user's computer. This vulnerability affects Firefox ESR < 60.7.2, Firefox < 67.0.4, and Thunderbird < 60.7.2.
Test IDs: 1.3.6.1.4.1.25623.1.0.815147   1.3.6.1.4.1.25623.1.1.4.2019.1684.1   1.3.6.1.4.1.25623.1.0.815145   1.3.6.1.4.1.25623.1.0.815146   1.3.6.1.4.1.25623.1.1.4.2019.1682.1   1.3.6.1.4.1.25623.1.0.704474   1.3.6.1.4.1.25623.1.2.1.2019.19   1.3.6.1.4.1.25623.1.0.852914   1.3.6.1.4.1.25623.1.1.13.2019.172.01   1.3.6.1.4.1.25623.1.0.844067   1.3.6.1.4.1.25623.1.0.876525   1.3.6.1.4.1.25623.1.1.10.2019.0202   1.3.6.1.4.1.25623.1.0.876524   1.3.6.1.4.1.25623.1.0.815144  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2019-11708
https://security.gentoo.org/glsa/201908-12
http://packetstormsecurity.com/files/155592/Mozilla-Firefox-Windows-64-Bit-Chain-Exploit.html
https://bugzilla.mozilla.org/show_bug.cgi?id=1559858
https://www.mozilla.org/security/advisories/mfsa2019-19/
https://www.mozilla.org/security/advisories/mfsa2019-20/




© 1998-2025 E-Soft Inc. All rights reserved.