CVE-2019-11699Mozilla Firefox vulnerability

10 documents5 sources
Severity
6.5MEDIUMNVD
OSV9.8
EPSS
0.2%
top 57.62%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 23
Latest updateMay 24

Description

A malicious page can briefly cause the wrong name to be highlighted as the domain name in the addressbar during page navigations. This could result in user confusion of which site is currently loaded for spoofing attacks. This vulnerability affects Firefox < 67.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:NExploitability: 2.8 | Impact: 3.6

Affected Packages4 packages

debiandebian/firefox< firefox 67.0-2 (sid)
CVEListV5mozilla/firefoxunspecified67
NVDmozilla/firefox< 67.0
Ubuntumozilla/firefox< 67.0+build2-0ubuntu0.16.04.1+5

🔴Vulnerability Details

5
GHSA
GHSA-53j8-j7vh-wcw7: A malicious page can briefly cause the wrong name to be highlighted as the domain name in the addressbar during page navigations2022-05-24
OSV
firefox regression2019-06-14
OSV
firefox regression2019-06-06
OSV
CVE-2019-11699: A malicious page can briefly cause the wrong name to be highlighted as the domain name in the addressbar during page navigations2019-05-21
OSV
firefox vulnerabilities2019-05-21

📋Vendor Advisories

4
Ubuntu
Firefox regression2019-06-14
Ubuntu
Firefox regression2019-06-06
Ubuntu
Firefox vulnerabilities2019-05-21
Debian
CVE-2019-11699: firefox - A malicious page can briefly cause the wrong name to be highlighted as the domai...2019