CVE-2019-0218
published 2019-04-22CVE-2019-0218: A vulnerability was discovered wherein a specially crafted URL could enable reflected XSS via JavaScript in the pony mail interface.
PriorityP428medium6.1CVSS 3.0
AVNACLPRNUIRSCCLILAN
EPSS
5.08%
91.3th percentile
A vulnerability was discovered wherein a specially crafted URL could enable reflected XSS via JavaScript in the pony mail interface.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | pony_mail | 0.8 – 0.10 | — |
| the_apache_software_foundation | apache_pony_mail | — | — |
CVSS provenance
nvdv3.06.1MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2018-18501 Mozilla: Memory safety bugs fixed in Firefox 65 and Firefox ESR 60.5
bugzilla·2019-01-29·CVSS 9.8
CVE-2018-18501 [CRITICAL] CVE-2018-18501 Mozilla: Memory safety bugs fixed in Firefox 65 and Firefox ESR 60.5
CVE-2018-18501 Mozilla: Memory safety bugs fixed in Firefox 65 and Firefox ESR 60.5
Mozilla developers and community members reported memory safety bugs present in Firefox 64 and Firefox ESR 60.4. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code.
External Reference:
https://www.mozilla.org/en-US/security/advisories/mfsa2019-02/#CVE-2018-18501
Discussion:
Acknowledgments:
Name: the Mozilla project
Upstream: Alex Gaynor, Christoph Diehl, Steven Crane, Jason Kratzer, Gary Kwong, Christian Holler
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6
Via RHSA-2019:0218 https://access.redhat.com/errata/RHSA-2019:0218
---
This issue has been addr
Bugzilla
CVE-2018-18500 Mozilla: Use-after-free parsing HTML5 stream
bugzilla·2019-01-29·CVSS 9.8
CVE-2018-18500 [CRITICAL] CVE-2018-18500 Mozilla: Use-after-free parsing HTML5 stream
CVE-2018-18500 Mozilla: Use-after-free parsing HTML5 stream
A use-after-free vulnerability can occur while parsing an HTML5 stream in concert with custom HTML elements. This results in the stream parser object being freed while still in use, leading to a potentially exploitable crash.
External Reference:
https://www.mozilla.org/en-US/security/advisories/mfsa2019-02/#CVE-2018-18500
Discussion:
Acknowledgments:
Name: the Mozilla project
Upstream: Yaniv Frank (SophosLabs)
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6
Via RHSA-2019:0218 https://access.redhat.com/errata/RHSA-2019:0218
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2019:0219 https://access.redhat.com/errata/RHSA-2019:0219
http://www.securityfocus.com/bid/108046https://lists.apache.org/thread.html/18a7ff26bc31a77e32e5e02e65dc86b1c41b610c753f8927d2cf955a%40%3Cdev.ponymail.apache.org%3Ehttps://www.openwall.com/lists/oss-security/2019/04/20/1http://www.securityfocus.com/bid/108046https://lists.apache.org/thread.html/18a7ff26bc31a77e32e5e02e65dc86b1c41b610c753f8927d2cf955a%40%3Cdev.ponymail.apache.org%3Ehttps://www.openwall.com/lists/oss-security/2019/04/20/1
2019-04-22
Published