The Vigil@nce team watches public vulnerabilities impacting your computers, and then offers security solutions, a database and tools to fix them.

Computer vulnerabilities of Firefox

cybersecurity bulletin CVE-2019-15903

libexpat: out-of-bounds memory reading via XML_GetCurrentLineNumber

Synthesis of the vulnerability

An attacker can force a read at an invalid address via XML_GetCurrentLineNumber() of libexpat, in order to trigger a denial of service, or to obtain sensitive information.
Severity: 2/4.
Creation date: 09/09/2019.
Identifiers: CERTFR-2019-AVI-535, CVE-2019-15903, DLA-1912-1, DLA-1987-1, DSA-4530-1, DSA-4549-1, FEDORA-2019-672ae0f060, FEDORA-2019-9505c6b555, FEDORA-2019-9b4ebc2973, MFSA-2019-33, MFSA-2019-34, MFSA-2019-35, openSUSE-SU-2019:2204-1, openSUSE-SU-2019:2205-1, openSUSE-SU-2019:2420-1, openSUSE-SU-2019:2424-1, openSUSE-SU-2019:2425-1, openSUSE-SU-2019:2447-1, openSUSE-SU-2019:2451-1, openSUSE-SU-2019:2452-1, openSUSE-SU-2019:2459-1, openSUSE-SU-2019:2464-1, RHSA-2019:3210-01, RHSA-2019:3237-01, RHSA-2019:3756-01, SSA:2019-259-01, SSA:2019-293-01, SSA:2019-295-01, SUSE-SU-2019:2429-1, SUSE-SU-2019:2440-1, SUSE-SU-2019:2871-1, SUSE-SU-2019:2872-1, SUSE-SU-2019:2912-1, USN-4132-1, USN-4132-2, USN-4165-1, USN-4165-2, VIGILANCE-VUL-30268.
Full Vigil@nce bulletin... (Free trial)

Description of the vulnerability

An attacker can force a read at an invalid address via XML_GetCurrentLineNumber() of libexpat, in order to trigger a denial of service, or to obtain sensitive information.
Full Vigil@nce bulletin... (Free trial)

computer weakness alert CVE-2019-5849

Skia: out-of-bounds memory reading

Synthesis of the vulnerability

An attacker can force a read at an invalid address of Skia, in order to trigger a denial of service, or to obtain sensitive information.
Severity: 2/4.
Creation date: 03/09/2019.
Identifiers: CVE-2019-5849, DSA-4500-1, MFSA-2019-25, MFSA-2019-26, openSUSE-SU-2019:1848-1, openSUSE-SU-2019:1849-1, openSUSE-SU-2019:1853-1, openSUSE-SU-2019:1901-1, RHSA-2019:2427-01, USN-4122-1, VIGILANCE-VUL-30234.
Full Vigil@nce bulletin... (Free trial)

Description of the vulnerability

An attacker can force a read at an invalid address of Skia, in order to trigger a denial of service, or to obtain sensitive information.
Full Vigil@nce bulletin... (Free trial)

computer vulnerability bulletin CVE-2019-11733

Firefox: information disclosure via Stored Passwords Copy

Synthesis of the vulnerability

An attacker can bypass access restrictions to data via Stored Passwords Copy of Firefox, in order to obtain sensitive information.
Severity: 1/4.
Creation date: 19/08/2019.
Identifiers: CERTFR-2019-AVI-400, CVE-2019-11733, MFSA-2019-24, openSUSE-SU-2019:2251-1, openSUSE-SU-2019:2260-1, RHSA-2019:2694-01, RHSA-2019:2729-01, SSA:2019-226-02, SUSE-SU-2019:2545-1, SUSE-SU-2019:2620-1, USN-4101-1, VIGILANCE-VUL-30056.
Full Vigil@nce bulletin... (Free trial)

Description of the vulnerability

An attacker can bypass access restrictions to data via Stored Passwords Copy of Firefox, in order to obtain sensitive information.
Full Vigil@nce bulletin... (Free trial)

cybersecurity announce CVE-2019-11702

Firefox: file reading via IE.HTTP Protocol

Synthesis of the vulnerability

A local attacker can read a file via IE.HTTP Protocol of Firefox, in order to obtain sensitive information.
Severity: 2/4.
Creation date: 12/06/2019.
Identifiers: CERTFR-2019-AVI-260, CVE-2019-11702, FEDORA-2019-c22338aa23, MFSA-2019-16, VIGILANCE-VUL-29522.
Full Vigil@nce bulletin... (Free trial)

Description of the vulnerability

A local attacker can read a file via IE.HTTP Protocol of Firefox, in order to obtain sensitive information.
Full Vigil@nce bulletin... (Free trial)

cybersecurity weakness CVE-2018-18335

Skia: buffer overflow via Canvas 2D

Synthesis of the vulnerability

An attacker can trigger a buffer overflow via Canvas 2D of Skia, in order to trigger a denial of service, and possibly to run code.
Severity: 3/4.
Creation date: 14/02/2019.
Identifiers: CERTFR-2019-AVI-058, CVE-2018-18335, MFSA-2019-05, openSUSE-SU-2019:0202-1, openSUSE-SU-2019:0249-1, openSUSE-SU-2019:0250-1, openSUSE-SU-2019:0251-1, openSUSE-SU-2019:1162-1, SSA:2019-044-01, SSA:2019-045-01, SUSE-SU-2019:0469-1, SUSE-SU-2019:0852-1, SUSE-SU-2019:0853-1, SUSE-SU-2019:0871-1, VIGILANCE-VUL-28511.
Full Vigil@nce bulletin... (Free trial)

Description of the vulnerability

An attacker can trigger a buffer overflow via Canvas 2D of Skia, in order to trigger a denial of service, and possibly to run code.
Full Vigil@nce bulletin... (Free trial)

computer threat CVE-2018-18511

Firefox: information disclosure via ImageBitmapRenderingContext

Synthesis of the vulnerability

An attacker can bypass access restrictions to data via ImageBitmapRenderingContext of Firefox, in order to obtain sensitive information.
Severity: 2/4.
Creation date: 13/02/2019.
Identifiers: bulletinapr2019, CERTFR-2019-AVI-058, CVE-2018-18511, DLA-1800-1, DSA-4448-1, FEDORA-2019-0a381a82de, FEDORA-2019-3b8d06c61e, FEDORA-2019-7ad9201e59, MFSA-2019-04, MFSA-2019-05, MFSA-2019-14, MFSA-2019-15, openSUSE-SU-2019:1484-1, openSUSE-SU-2019:1534-1, openSUSE-SU-2019:1664-1, RHSA-2019:1265-01, RHSA-2019:1267-01, RHSA-2019:1269-01, RHSA-2019:1308-01, RHSA-2019:1309-01, RHSA-2019:1310-01, SUSE-SU-2019:14114-1, SUSE-SU-2019:1458-1, USN-3896-1, USN-3997-1, VIGILANCE-VUL-28503.
Full Vigil@nce bulletin... (Free trial)

Description of the vulnerability

An attacker can bypass access restrictions to data via ImageBitmapRenderingContext of Firefox, in order to obtain sensitive information.
Full Vigil@nce bulletin... (Free trial)

computer vulnerability note CVE-2019-5785

Skia: integer overflow via Transform Operations

Synthesis of the vulnerability

An attacker can trigger an integer overflow via Transform Operations of Skia, in order to trigger a denial of service, and possibly to run code.
Severity: 3/4.
Creation date: 13/02/2019.
Identifiers: bulletinjan2019, CERTFR-2019-AVI-058, CVE-2019-5785, DLA-1677-1, DLA-1678-1, DSA-4391-1, DSA-4392-1, MFSA-2019-04, MFSA-2019-05, openSUSE-SU-2019:0202-1, openSUSE-SU-2019:0248-1, openSUSE-SU-2019:0249-1, openSUSE-SU-2019:0250-1, openSUSE-SU-2019:0251-1, openSUSE-SU-2019:1162-1, RHSA-2019:0373-01, RHSA-2019:0374-01, SSA:2019-044-01, SSA:2019-045-01, SUSE-SU-2019:0469-1, SUSE-SU-2019:0852-1, SUSE-SU-2019:0853-1, SUSE-SU-2019:0871-1, USN-3896-1, USN-3897-1, VIGILANCE-VUL-28502.
Full Vigil@nce bulletin... (Free trial)

Description of the vulnerability

An attacker can trigger an integer overflow via Transform Operations of Skia, in order to trigger a denial of service, and possibly to run code.
Full Vigil@nce bulletin... (Free trial)

security threat CVE-2018-18356

Skia: use after free via Path Creation

Synthesis of the vulnerability

An attacker can force the usage of a freed memory area via Path Creation of Skia, in order to trigger a denial of service, and possibly to run code.
Severity: 3/4.
Creation date: 13/02/2019.
Identifiers: bulletinapr2019, bulletinjan2019, CERTFR-2019-AVI-058, CVE-2018-18356, DLA-1677-1, DLA-1678-1, DSA-4391-1, DSA-4392-1, MFSA-2019-04, MFSA-2019-05, openSUSE-SU-2019:0202-1, openSUSE-SU-2019:0248-1, openSUSE-SU-2019:0249-1, openSUSE-SU-2019:0250-1, openSUSE-SU-2019:0251-1, openSUSE-SU-2019:1162-1, RHSA-2019:0373-01, RHSA-2019:0374-01, SSA:2019-044-01, SSA:2019-045-01, SUSE-SU-2019:0469-1, SUSE-SU-2019:0852-1, SUSE-SU-2019:0853-1, SUSE-SU-2019:0871-1, USN-3896-1, USN-3897-1, VIGILANCE-VUL-28501.
Full Vigil@nce bulletin... (Free trial)

Description of the vulnerability

An attacker can force the usage of a freed memory area via Path Creation of Skia, in order to trigger a denial of service, and possibly to run code.
Full Vigil@nce bulletin... (Free trial)

threat announce CVE-2019-7317

libpng: use after free via png_image_free

Synthesis of the vulnerability

An attacker can force the usage of a freed memory area via png_image_free() of libpng, in order to trigger a denial of service, and possibly to run code.
Severity: 2/4.
Creation date: 05/02/2019.
Identifiers: 1087227, 275, bulletinapr2019, cpujul2019, CVE-2019-7317, DSA-4435-1, FEDORA-2019-146b81efba, FEDORA-2019-3854a1727e, FEDORA-2019-5c794ec7ba, FEDORA-2019-a5ec38072a, MFSA-2019-14, MFSA-2019-15, openSUSE-SU-2019:1484-1, openSUSE-SU-2019:1530-1, openSUSE-SU-2019:1534-1, openSUSE-SU-2019:1664-1, openSUSE-SU-2019:1912-1, openSUSE-SU-2019:1916-1, RHSA-2019:1308-01, RHSA-2019:1309-01, RHSA-2019:1310-01, RHSA-2019:2494-01, RHSA-2019:2495-01, RHSA-2019:2585-01, RHSA-2019:2590-01, RHSA-2019:2592-01, SSA:2019-107-01, SUSE-SU-2019:1388-1, SUSE-SU-2019:1398-1, SUSE-SU-2019:1398-2, SUSE-SU-2019:1405-1, SUSE-SU-2019:14160-1, SUSE-SU-2019:14188-1, SUSE-SU-2019:1458-1, SUSE-SU-2019:2021-1, SUSE-SU-2019:2028-1, SUSE-SU-2019:2036-1, SUSE-SU-2019:2291-1, SUSE-SU-2019:2336-1, SUSE-SU-2019:2371-1, USN-3962-1, USN-4080-1, USN-4083-1, VIGILANCE-VUL-28437.
Full Vigil@nce bulletin... (Free trial)

Description of the vulnerability

An attacker can force the usage of a freed memory area via png_image_free() of libpng, in order to trigger a denial of service, and possibly to run code.
Full Vigil@nce bulletin... (Free trial)

vulnerability bulletin 27815

Firefox: denial of service

Synthesis of the vulnerability

An attacker can generate a fatal error of Firefox, in order to trigger a denial of service.
Severity: 2/4.
Creation date: 19/11/2018.
Identifiers: 1498510, FEDORA-2018-7653b2c491, FEDORA-2018-b07a7b4ae1, USN-3801-1, USN-3801-2, VIGILANCE-VUL-27815.
Full Vigil@nce bulletin... (Free trial)

Description of the vulnerability

An attacker can generate a fatal error of Firefox, in order to trigger a denial of service.
Full Vigil@nce bulletin... (Free trial)
Our database contains other pages. You can request a free trial to read them.

Display information about Firefox: