CVE-2019-2663
published 2019-04-23CVE-2019-2663: Vulnerability in the Oracle Advanced Outbound Telephony component of Oracle E-Business Suite (subcomponent: User Interface). Supported versions that are…
PriorityP343high8.2CVSS 3.0
AVNACLPRNUIRSCCHILAN
EPSS
1.29%
66.8th percentile
Vulnerability in the Oracle Advanced Outbound Telephony component of Oracle E-Business Suite (subcomponent: User Interface). Supported versions that are affected are 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6, 12.2.7 and 12.2.8. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Advanced Outbound Telephony. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Advanced Outbound Telephony, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Advanced Outbound Telephony accessible data as well as unauthorized update, insert or delete access to some of Oracle Advanced Outbound Telephony accessible data. CVSS 3.0 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N).
Affected
18 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| oracle | advanced_outbound_telephony | — | — |
| oracle | advanced_outbound_telephony | — | — |
| oracle | advanced_outbound_telephony | — | — |
| oracle | advanced_outbound_telephony | — | — |
| oracle | advanced_outbound_telephony | — | — |
| oracle | advanced_outbound_telephony | — | — |
| oracle | advanced_outbound_telephony | — | — |
| oracle | advanced_outbound_telephony | — | — |
| oracle | advanced_outbound_telephony | — | — |
| oracle_corporation | advanced_outbound_telephony | — | — |
| oracle_corporation | advanced_outbound_telephony | — | — |
| oracle_corporation | advanced_outbound_telephony | — | — |
| oracle_corporation | advanced_outbound_telephony | — | — |
| oracle_corporation | advanced_outbound_telephony | — | — |
| oracle_corporation | advanced_outbound_telephony | — | — |
| oracle_corporation | advanced_outbound_telephony | — | — |
| oracle_corporation | advanced_outbound_telephony | — | — |
| oracle_corporation | advanced_outbound_telephony | — | — |
CVSS provenance
nvdv3.08.2HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N
nvdv2.05.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2019-11742 Mozilla: Same-origin policy violation with SVG filters and canvas to steal cross-origin images
bugzilla·2019-09-04·CVSS 6.5
CVE-2019-11742 [MEDIUM] CVE-2019-11742 Mozilla: Same-origin policy violation with SVG filters and canvas to steal cross-origin images
CVE-2019-11742 Mozilla: Same-origin policy violation with SVG filters and canvas to steal cross-origin images
A same-origin policy violation occurs allowing the theft of cross-origin images through a combination of SVG filters and a `` element due to an error in how same-origin policy is applied to cached image content. The resulting same-origin policy violation could allow for data theft.
External Reference:
https://www.mozilla.org/en-US/security/advisories/mfsa2019-27/#CVE-2019-11742
Discussion:
Acknowledgments:
Name: the Mozilla project
Upstream: Paul Stone
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2019:2663 https://access.redhat.com/errata/RHSA-2019:2663
---
This bug is now closed. Further updates for individual produc
Bugzilla
CVE-2019-11743 Mozilla: Cross-origin access to unload event attributes
bugzilla·2019-09-04·CVSS 3.7
CVE-2019-11743 [LOW] CVE-2019-11743 Mozilla: Cross-origin access to unload event attributes
CVE-2019-11743 Mozilla: Cross-origin access to unload event attributes
Navigation events were not fully adhering to the W3C's "Navigation-Timing Level 2" draft specification in some instances for the `unload` event, which restricts access to detailed timing attributes to only be same-origin. This resulted in potential cross-origin information exposure of history through timing side-channel attacks.
External Reference:
https://www.mozilla.org/en-US/security/advisories/mfsa2019-27/#CVE-2019-11743
Discussion:
Acknowledgments:
Name: the Mozilla project
Upstream: Yoav Weiss
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2019:2663 https://access.redhat.com/errata/RHSA-2019:2663
---
This bug is now closed. Further updates for individu
Bugzilla
CVE-2019-11746 Mozilla: Use-after-free while manipulating video
bugzilla·2019-09-04·CVSS 8.8
CVE-2019-11746 [HIGH] CVE-2019-11746 Mozilla: Use-after-free while manipulating video
CVE-2019-11746 Mozilla: Use-after-free while manipulating video
A use-after-free vulnerability can occur while manipulating video elements if the body is freed while still in use. This results in a potentially exploitable crash.
External Reference:
https://www.mozilla.org/en-US/security/advisories/mfsa2019-27/#CVE-2019-11746
Discussion:
Acknowledgments:
Name: the Mozilla project
Upstream: Nils
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2019:2663 https://access.redhat.com/errata/RHSA-2019:2663
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-2019-11746
---
This issue has been addressed in the following products:
Red Hat En
Bugzilla
CVE-2019-11750 Mozilla: Type confusion in Spidermonkey
bugzilla·2019-09-04·CVSS 6.5
CVE-2019-11750 [MEDIUM] CVE-2019-11750 Mozilla: Type confusion in Spidermonkey
CVE-2019-11750 Mozilla: Type confusion in Spidermonkey
A type confusion vulnerability exists in Spidermonkey, which results in a non-exploitable crash.
External Reference:
https://www.mozilla.org/en-US/security/advisories/mfsa2019-26/#CVE-2019-11750
Discussion:
Acknowledgments:
Name: the Mozilla project
Upstream: Qixun Zhao (Qihoo 360 Vulcan Team)
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2019:2663 https://access.redhat.com/errata/RHSA-2019:2663
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-2019-11750
Bugzilla
CVE-2019-9812 Mozilla: Sandbox escape through Firefox Sync
bugzilla·2019-09-04·CVSS 9.3
CVE-2019-9812 [CRITICAL] CVE-2019-9812 Mozilla: Sandbox escape through Firefox Sync
CVE-2019-9812 Mozilla: Sandbox escape through Firefox Sync
Given a compromised sandboxed content process due to a separate vulnerability, it is possible to escape that sandbox by loading `accounts.firefox.com` in that process and forcing a log-in to a malicious Firefox Sync account. Preference settings that disable the sandbox are then synchronized to the local machine and the compromised browser would restart without the sandbox if a crash is triggered.
External Reference:
https://www.mozilla.org/en-US/security/advisories/mfsa2019-27/#CVE-2019-9812
Discussion:
Acknowledgments:
Name: the Mozilla project
Upstream: Niklas Baumstark via TrendMicro's Zero Day Initiative
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2019:2663 https:/
Bugzilla
CVE-2019-11744 Mozilla: XSS by breaking out of title and textarea elements using innerHTML
bugzilla·2019-09-04·CVSS 6.1
CVE-2019-11744 [MEDIUM] CVE-2019-11744 Mozilla: XSS by breaking out of title and textarea elements using innerHTML
CVE-2019-11744 Mozilla: XSS by breaking out of title and textarea elements using innerHTML
Some HTML elements, such as `` and ``, can contain literal angle brackets without treating them as markup. It is possible to pass a literal closing tag to `.innerHTML` on these elements, and subsequent content after that will be parsed as if it were outside the tag. This can lead to XSS if a site does not filter user input as strictly for these elements as it does for other elements.
External Reference:
https://www.mozilla.org/en-US/security/advisories/mfsa2019-27/#CVE-2019-11744
Discussion:
Acknowledgments:
Name: the Mozilla project
Upstream: Rakesh Mane
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2019:2663 https://access.redhat.com/err
Bugzilla
CVE-2019-11740 Mozilla: Memory safety bugs fixed in Firefox 69, Firefox ESR 68.1, Firefox ESR 60.9, Thunderbird 68.1, and Thunderbird 60.9
bugzilla·2019-09-04·CVSS 8.8
CVE-2019-11740 [HIGH] CVE-2019-11740 Mozilla: Memory safety bugs fixed in Firefox 69, Firefox ESR 68.1, Firefox ESR 60.9, Thunderbird 68.1, and Thunderbird 60.9
CVE-2019-11740 Mozilla: Memory safety bugs fixed in Firefox 69, Firefox ESR 68.1, Firefox ESR 60.9, Thunderbird 68.1, and Thunderbird 60.9
Mozilla developers and community members reported memory safety bugs present in Firefox 68, Firefox ESR 68, and Firefox 60.8. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code.
External Reference:
https://www.mozilla.org/en-US/security/advisories/mfsa2019-27/#CVE-2019-11740
Discussion:
Acknowledgments:
Name: the Mozilla project
Upstream: Tyson Smith, Nathan Froyd
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2019:2663 https://access.redhat.com/errata/RHSA-2019:2663
---
This bug is now cl
Bugzilla
CVE-2019-11738 Mozilla: Content security policy bypass through hash-based sources in directives
bugzilla·2019-09-04·CVSS 6.3
CVE-2019-11738 [MEDIUM] CVE-2019-11738 Mozilla: Content security policy bypass through hash-based sources in directives
CVE-2019-11738 Mozilla: Content security policy bypass through hash-based sources in directives
If a Content Security Policy (CSP) directive is defined that uses a hash-based source that takes the empty string as input, execution of any `javascript:` URIs will be allowed. This could allow for malicious JavaScript content to be run, bypassing CSP permissions.
External Reference:
https://www.mozilla.org/en-US/security/advisories/mfsa2019-26/#CVE-2019-11738
Discussion:
Acknowledgments:
Name: the Mozilla project
Upstream: Wladimir Palant
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2019:2663 https://access.redhat.com/errata/RHSA-2019:2663
---
This bug is now closed. Further updates for individual products will be reflected on the
Bugzilla
CVE-2019-11752 Mozilla: Use-after-free while extracting a key value in IndexedDB
bugzilla·2019-09-04·CVSS 8.8
CVE-2019-11752 [HIGH] CVE-2019-11752 Mozilla: Use-after-free while extracting a key value in IndexedDB
CVE-2019-11752 Mozilla: Use-after-free while extracting a key value in IndexedDB
It is possible to delete an IndexedDB key value and subsequently try to extract it during conversion. This results in a use-after-free and a potentially exploitable crash.
External Reference:
https://www.mozilla.org/en-US/security/advisories/mfsa2019-27/#CVE-2019-11752
Discussion:
Acknowledgments:
Name: the Mozilla project
Upstream: Zhanjia Song
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2019:2663 https://access.redhat.com/errata/RHSA-2019:2663
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-2019-11752
---
This issue has been addressed in the
Bugzilla
CVE-2019-11749 Mozilla: Camera information available without prompting using getUserMedia
bugzilla·2019-09-04·CVSS 4.3
CVE-2019-11749 [MEDIUM] CVE-2019-11749 Mozilla: Camera information available without prompting using getUserMedia
CVE-2019-11749 Mozilla: Camera information available without prompting using getUserMedia
A vulnerability exists in WebRTC where malicious web content can use probing techniques on the `getUserMedia` API using constraints to reveal device properties of cameras on the system without triggering a user prompt or notification. This allows for the potential fingerprinting of users.
External Reference:
https://www.mozilla.org/en-US/security/advisories/mfsa2019-26/#CVE-2019-11749
Discussion:
Acknowledgments:
Name: the Mozilla project
Upstream: Andreas Pehrson
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2019:2663 https://access.redhat.com/errata/RHSA-2019:2663
---
This bug is now closed. Further updates for individual products will
Bugzilla
CVE-2019-11735 Mozilla: Memory safety bugs fixed in Firefox 69 and Firefox ESR 68.1
bugzilla·2019-09-04·CVSS 8.8
CVE-2019-11735 [HIGH] CVE-2019-11735 Mozilla: Memory safety bugs fixed in Firefox 69 and Firefox ESR 68.1
CVE-2019-11735 Mozilla: Memory safety bugs fixed in Firefox 69 and Firefox ESR 68.1
Mozilla developers and community members reported memory safety bugs present in Firefox 68 and Firefox ESR 68. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code.
External Reference:
https://www.mozilla.org/en-US/security/advisories/mfsa2019-26/#CVE-2019-11735
Discussion:
Acknowledgments:
Name: the Mozilla project
Upstream: Mikhail Gavrilov, Tyson Smith, Marcia Knous, Tom Ritter, Philipp, Bob Owens
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2019:2663 https://access.redhat.com/errata/RHSA-2019:2663
---
This bug is now closed. Further update
2019-04-23
Published