CVE-2019-11715

Due to an error while parsing page content, it is possible for properly sanitized user input to be misinterpreted and lead to XSS hazards on web sites in certain circumstances. This vulnerability affects Firefox ESR < 60.8, Firefox < 68, and Thunderbird < 60.8.
References
Link Resource
http://lists.opensuse.org/opensuse-security-announce/2019-07/msg00055.html
http://lists.opensuse.org/opensuse-security-announce/2019-07/msg00058.html
http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00073.html
http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00009.html
http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00010.html
https://bugzilla.mozilla.org/show_bug.cgi?id=1555523 Issue Tracking Permissions Required Vendor Advisory
https://lists.debian.org/debian-lts-announce/2019/08/msg00001.html
https://lists.debian.org/debian-lts-announce/2019/08/msg00002.html
https://security.gentoo.org/glsa/201908-12
https://security.gentoo.org/glsa/201908-20
https://www.mozilla.org/security/advisories/mfsa2019-21/ Vendor Advisory
https://www.mozilla.org/security/advisories/mfsa2019-22/ Vendor Advisory
https://www.mozilla.org/security/advisories/mfsa2019-23/ Vendor Advisory
http://lists.opensuse.org/opensuse-security-announce/2019-07/msg00055.html
http://lists.opensuse.org/opensuse-security-announce/2019-07/msg00058.html
http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00073.html
http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00009.html
http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00010.html
https://bugzilla.mozilla.org/show_bug.cgi?id=1555523 Issue Tracking Permissions Required Vendor Advisory
https://lists.debian.org/debian-lts-announce/2019/08/msg00001.html
https://lists.debian.org/debian-lts-announce/2019/08/msg00002.html
https://security.gentoo.org/glsa/201908-12
https://security.gentoo.org/glsa/201908-20
https://www.mozilla.org/security/advisories/mfsa2019-21/ Vendor Advisory
https://www.mozilla.org/security/advisories/mfsa2019-22/ Vendor Advisory
https://www.mozilla.org/security/advisories/mfsa2019-23/ Vendor Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox_esr:*:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*

History

21 Nov 2024, 04:21

Type Values Removed Values Added
References () http://lists.opensuse.org/opensuse-security-announce/2019-07/msg00055.html - () http://lists.opensuse.org/opensuse-security-announce/2019-07/msg00055.html -
References () http://lists.opensuse.org/opensuse-security-announce/2019-07/msg00058.html - () http://lists.opensuse.org/opensuse-security-announce/2019-07/msg00058.html -
References () http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00073.html - () http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00073.html -
References () http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00009.html - () http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00009.html -
References () http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00010.html - () http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00010.html -
References () https://bugzilla.mozilla.org/show_bug.cgi?id=1555523 - Issue Tracking, Permissions Required, Vendor Advisory () https://bugzilla.mozilla.org/show_bug.cgi?id=1555523 - Issue Tracking, Permissions Required, Vendor Advisory
References () https://lists.debian.org/debian-lts-announce/2019/08/msg00001.html - () https://lists.debian.org/debian-lts-announce/2019/08/msg00001.html -
References () https://lists.debian.org/debian-lts-announce/2019/08/msg00002.html - () https://lists.debian.org/debian-lts-announce/2019/08/msg00002.html -
References () https://security.gentoo.org/glsa/201908-12 - () https://security.gentoo.org/glsa/201908-12 -
References () https://security.gentoo.org/glsa/201908-20 - () https://security.gentoo.org/glsa/201908-20 -
References () https://www.mozilla.org/security/advisories/mfsa2019-21/ - Vendor Advisory () https://www.mozilla.org/security/advisories/mfsa2019-21/ - Vendor Advisory
References () https://www.mozilla.org/security/advisories/mfsa2019-22/ - Vendor Advisory () https://www.mozilla.org/security/advisories/mfsa2019-22/ - Vendor Advisory
References () https://www.mozilla.org/security/advisories/mfsa2019-23/ - Vendor Advisory () https://www.mozilla.org/security/advisories/mfsa2019-23/ - Vendor Advisory

Information

Published : 2019-07-23 14:15

Updated : 2024-11-21 04:21


NVD link : CVE-2019-11715

Mitre link : CVE-2019-11715

CVE.ORG link : CVE-2019-11715


JSON object : View

Products Affected

mozilla

  • firefox
  • thunderbird
  • firefox_esr
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')