Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2019-11743
Description:Navigation events were not fully adhering to the W3C's "Navigation- Timing Level 2" draft specification in some instances for the unload event, which restricts access to detailed timing attributes to only be same-origin. This resulted in potential cross-origin information exposure of history through timing side-channel attacks. This vulnerability affects Firefox < 69, Thunderbird < 68.1, Thunderbird < 60.9, Firefox ESR < 60.9, and Firefox ESR < 68.1.
Test IDs: 1.3.6.1.4.1.25623.1.1.4.2019.14173.1  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2019-11743
https://security.gentoo.org/glsa/201911-07
https://bugzilla.mozilla.org/show_bug.cgi?id=1560495
https://w3c.github.io/navigation-timing
SuSE Security Announcement: openSUSE-SU-2019:2248 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00010.html
SuSE Security Announcement: openSUSE-SU-2019:2249 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00009.html
SuSE Security Announcement: openSUSE-SU-2019:2251 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00011.html
SuSE Security Announcement: openSUSE-SU-2019:2260 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00017.html
https://usn.ubuntu.com/4150-1/




© 1998-2025 E-Soft Inc. All rights reserved.