CVE-2019-9801
published 2019-04-26CVE-2019-9801: Firefox will accept any registered Program ID as an external protocol handler and offer to launch this local application when given a matching URL on Windows…
PriorityP424medium5.3CVSS 3.0
AVNACLPRNUINSUCNILAN
EPSS
1.31%
67.7th percentile
Firefox will accept any registered Program ID as an external protocol handler and offer to launch this local application when given a matching URL on Windows operating systems. This should only happen if the program has specifically registered itself as a "URL Handler" in the Windows registry. *Note: This issue only affects Windows operating systems. Other operating systems are unaffected.*. This vulnerability affects Thunderbird < 60.6, Firefox ESR < 60.6, and Firefox < 66.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | firefox | — | — |
| debian | firefox-esr | — | — |
| debian | thunderbird | — | — |
| mozilla | firefox | < 66.0 | 66.0 |
| mozilla | firefox | >= unspecified < 66 | 66 |
| mozilla | firefox_esr | < 60.6 | 60.6 |
| mozilla | firefox_esr | >= unspecified < 60.6 | 60.6 |
| mozilla | thunderbird | < 60.6 | 60.6 |
| mozilla | thunderbird | >= unspecified < 60.6 | 60.6 |
CVSS provenance
nvdv3.05.3MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
osv5.3MEDIUM
vendor_debian5.3LOW
vendor_redhat5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
Mozilla: Windows programs that are not 'URL Handlers' are exposed to web content
vendor_redhat·2019-03-20·CVSS 5.3
CVE-2019-9801 [MEDIUM] CWE-88 Mozilla: Windows programs that are not 'URL Handlers' are exposed to web content
Mozilla: Windows programs that are not 'URL Handlers' are exposed to web content
Firefox will accept any registered Program ID as an external protocol handler and offer to launch this local application when given a matching URL on Windows operating systems. This should only happen if the program has specifically registered itself as a "URL Handler" in the Windows registry. *Note: This issue only affects Windows operating systems. Other operating systems are unaffected.*. This vulnerability affects Thunderbird < 60.6, Firefox ESR < 60.6, and Firefox < 66.
Statement: This issue does not affect the version of firefox and thunderbird as shipped with Red Hat Enterprise Linux 6 and 7.
Package: firefox (Red Hat Enterprise Linux 6) - Not affected
Package: thunderbird (Red Hat Enterprise Linux
Debian
CVE-2019-9801: firefox - Firefox will accept any registered Program ID as an external protocol handler an...
vendor_debian·2019·CVSS 5.3
CVE-2019-9801 [MEDIUM] CVE-2019-9801: firefox - Firefox will accept any registered Program ID as an external protocol handler an...
Firefox will accept any registered Program ID as an external protocol handler and offer to launch this local application when given a matching URL on Windows operating systems. This should only happen if the program has specifically registered itself as a "URL Handler" in the Windows registry. *Note: This issue only affects Windows operating systems. Other operating systems are unaffected.*. This vulnerability affects Thunderbird < 60.6, Firefox ESR < 60.6, and Firefox < 66.
Scope: local
sid: resolved
GHSA
GHSA-cr8h-fffv-pv55: Firefox will accept any registered Program ID as an external protocol handler and offer to launch this local application when given a matching URL on
ghsa_unreviewed·2022-05-24
CVE-2019-9801 [MEDIUM] CWE-20 GHSA-cr8h-fffv-pv55: Firefox will accept any registered Program ID as an external protocol handler and offer to launch this local application when given a matching URL on
Firefox will accept any registered Program ID as an external protocol handler and offer to launch this local application when given a matching URL on Windows operating systems. This should only happen if the program has specifically registered itself as a "URL Handler" in the Windows registry. *Note: This issue only affects Windows operating systems. Other operating systems are unaffected.*. This vulnerability affects Thunderbird < 60.6, Firefox ESR < 60.6, and Firefox < 66.
OSV
CVE-2019-9801: Firefox will accept any registered Program ID as an external protocol handler and offer to launch this local application when given a matching URL on
osv·2019-04-26·CVSS 5.3
CVE-2019-9801 [MEDIUM] CVE-2019-9801: Firefox will accept any registered Program ID as an external protocol handler and offer to launch this local application when given a matching URL on
Firefox will accept any registered Program ID as an external protocol handler and offer to launch this local application when given a matching URL on Windows operating systems. This should only happen if the program has specifically registered itself as a "URL Handler" in the Windows registry. *Note: This issue only affects Windows operating systems. Other operating systems are unaffected.*. This vulnerability affects Thunderbird < 60.6, Firefox ESR < 60.6, and Firefox < 66.
No detection rules found.
No public exploits indexed.
https://bugzilla.mozilla.org/show_bug.cgi?id=1527717https://www.mozilla.org/security/advisories/mfsa2019-07/https://www.mozilla.org/security/advisories/mfsa2019-08/https://www.mozilla.org/security/advisories/mfsa2019-11/https://bugzilla.mozilla.org/show_bug.cgi?id=1527717https://www.mozilla.org/security/advisories/mfsa2019-07/https://www.mozilla.org/security/advisories/mfsa2019-08/https://www.mozilla.org/security/advisories/mfsa2019-11/
2019-04-26
Published