CVE-2019-11699
UnknownEPSS 0.85%
Last modified
CVE-2019-11699 is a vulnerability of currently unknown severity. A malicious page can briefly cause the wrong name to be highlighted as the domain name in the addressbar during page navigations. This could result in user confusion of which site is currently loaded for spoofing attacks. EPSS estimates a 0.85% chance of exploitation in the next 30 days.
Description
A malicious page can briefly cause the wrong name to be highlighted as the domain name in the addressbar during page navigations. This could result in user confusion of which site is currently loaded for spoofing attacks. This vulnerability affects Firefox < 67.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Mozilla | Firefox | < 67.0 |
References
- https://bugzilla.mozilla.org/show_bug.cgi?id=1528939Issue Tracking, Permissions Required, Vendor Advisory
- https://www.mozilla.org/security/advisories/mfsa2019-13/Vendor Advisory
- https://bugzilla.mozilla.org/show_bug.cgi?id=1528939Issue Tracking, Permissions Required, Vendor Advisory
- https://www.mozilla.org/security/advisories/mfsa2019-13/Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2019-11699?
A malicious page can briefly cause the wrong name to be highlighted as the domain name in the addressbar during page navigations. This could result in user confusion of which site is currently loaded for spoofing attacks. This vulnerability affects Firefox < 67.
How severe is CVE-2019-11699?
Severity scoring for CVE-2019-11699 is pending analysis. The EPSS model estimates a 0.85% probability of exploitation in the next 30 days.
How do I fix CVE-2019-11699?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2019
- CVE-2019-11693The bufferdata function in WebGL is vulnerable to a buffer o…
- CVE-2019-11694A vulnerability exists in the Windows sandbox where an unini…
- CVE-2019-11695A custom cursor defined by scripting on a site can position …
- CVE-2019-11696Files with the .JNLP extension used for "Java web start" app…
- CVE-2019-11697If the ALT and "a" keys are pressed when users receive an ex…
- CVE-2019-11698If a crafted hyperlink is dragged and dropped to the bookmar…
- CVE-2019-1170An elevation of privilege vulnerability exists when reparse …7.9
- CVE-2019-11700A hyperlink using the res: protocol can be used to open loca…
- CVE-2019-11701The default webcal: protocol handler will load a web site vu…
- CVE-2019-11702A hyperlink using protocols associated with Internet Explore…
- CVE-2019-11703A flaw in Thunderbird's implementation of iCal causes a heap…9.8
- CVE-2019-11704A flaw in Thunderbird's implementation of iCal causes a heap…9.8
Are you affected by CVE-2019-11699?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
