PT-2019-4555 · Mozilla+3 · Firefox+3

Rakesh Mane

·

Published

2019-07-11

·

Updated

2024-12-12

·

CVE-2019-11720

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Firefox versions prior to 68
Description The issue is related to the incorrect handling of certain Unicode characters during web content parsing, which can lead to the execution of malicious code and evade cross-site scripting (XSS) filtering. This allows a remote attacker to impact data integrity.
Recommendations For versions prior to 68, update to version 68 or later to resolve the issue. As a temporary workaround, consider restricting access to potentially malicious web content to minimize the risk of exploitation.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2019-2301
ALT-PU-2019-2324
ALT-PU-2019-2479
ALT-PU-2019-2486
BDU:2020-00601
CVE-2019-11720
MGASA-2019-0213
MGASA-2019-0272
OPENSUSE-SU-2019:2248-1
OPENSUSE-SU-2019:2249-1
OPENSUSE-SU-2019:2251-1
OPENSUSE-SU-2019:2260-1
OPENSUSE-SU-2019_2248-1
OPENSUSE-SU-2019_2249-1
OPENSUSE-SU-2019_2251-1
OPENSUSE-SU-2019_2260-1
OPENSUSE-SU-2024:10600-1
OPENSUSE-SU-2024:14572-1
SUSE-SU-2019:14246-1
SUSE-SU-2019:2515-1
SUSE-SU-2019:2545-1
SUSE-SU-2019:2620-1
SUSE-SU-2019_14246-1
USN-4054-1
USN-4054-2

Affected Products

Alt Linux
Firefox
Suse
Ubuntu