CVE-2019-11708
Insufficient vetting of parameters passed with the Prompt:Open IPC message between child and parent processes can result in the non-sandboxed parent process opening web content chosen by a compromised child process. When combined with additional vulnerabilities this could result in executing arbitrary code on the user's computer. This vulnerability affects Firefox ESR < 60.7.2, Firefox < 67.0.4, and Thunderbird < 60.7.2.
- Affected products
- Alt Linux, Centos, Firefox, Firefox Esr, Red Hat, Suse, Thunderbird, Tor Browser
- Mozilla Firefox
- < 60.7.2, 67.0.4
- Mozilla Thunderbird
- < 60.7.2
- Fix
- Available
- CVSS 3.1
- 10.0 CRITICAL
- EPSS
- 55.9% (99th percentile)
- Weakness
- CWE-20
- NVD status
- Analyzed
- Published
- 2019-07-23
CVE-2019-11708 at NVD
13 known exploits for CVE-2019-11708
Proof-of-concept code and exploit modules indexed by Sploitus
CVE-2019-11708
CVE-2019-9791
Exploit for Improper Input Validation in Mozilla Firefox
Mozilla Firefox 67 - Array.pop JIT Type Confusion Exploit
Mozilla Firefox 67 - Array.pop JIT Type Confusion
Mozilla Firefox 67 Array.pop JIT Type Confusion
Exploit for Type Confusion in Mozilla Firefox
Exploit for Deserialization of Untrusted Data in Redhat Jboss_Enterprise_Application_Platform
Exploit for Deserialization of Untrusted Data in Redhat Jboss_Enterprise_Application_Platform
Mozilla FireFox (Windows 10 x64) - Full Chain Client Side Attack Exploit
Mozilla FireFox (Windows 10 x64) - Full Chain Client Side Attack
Mozilla FireFox (Windows 10 x64) - Full Chain Client Side Attack
Exploit for Improper Input Validation in Mozilla Firefox