CVE-2019-11715
Last modified
CVE-2019-11715 is a vulnerability of currently unknown severity. Due to an error while parsing page content, it is possible for properly sanitized user input to be misinterpreted and lead to XSS hazards on web sites in certain circumstances. This vulnerability affects Firefox ESR < 60.8, Firefox < 68, and Thunderbird < 60.8.. EPSS estimates a 1.50% chance of exploitation in the next 30 days.
Description
Due to an error while parsing page content, it is possible for properly sanitized user input to be misinterpreted and lead to XSS hazards on web sites in certain circumstances. This vulnerability affects Firefox ESR < 60.8, Firefox < 68, and Thunderbird < 60.8.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Mozilla | Firefox | < 60.8.0 |
| Mozilla | Firefox | < 68.0 |
| Mozilla | Thunderbird | < 60.8.0 |
References
- https://bugzilla.mozilla.org/show_bug.cgi?id=1555523Issue Tracking, Permissions Required, Vendor Advisory
- https://www.mozilla.org/security/advisories/mfsa2019-21/Vendor Advisory
- https://www.mozilla.org/security/advisories/mfsa2019-22/Vendor Advisory
- https://www.mozilla.org/security/advisories/mfsa2019-23/Vendor Advisory
- https://bugzilla.mozilla.org/show_bug.cgi?id=1555523Issue Tracking, Permissions Required, Vendor Advisory
- https://www.mozilla.org/security/advisories/mfsa2019-21/Vendor Advisory
- https://www.mozilla.org/security/advisories/mfsa2019-22/Vendor Advisory
- https://www.mozilla.org/security/advisories/mfsa2019-23/Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2019-11715?
How severe is CVE-2019-11715?
How do I fix CVE-2019-11715?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2019
- CVE-2019-1171An information disclosure vulnerability exists in SymCrypt d…5.6
- CVE-2019-11710Mozilla developers and community members reported memory saf…9.8
- CVE-2019-11711When an inner window is reused, it does not consider the use…8.8
- CVE-2019-11712POST requests made by NPAPI plugins, such as Flash, that rec…
- CVE-2019-11713A use-after-free vulnerability can occur in HTTP/2 when a ca…
- CVE-2019-11714Necko can access a child on the wrong thread during UDP conn…
- CVE-2019-11716Until explicitly accessed by script, window.globalThis is no…
- CVE-2019-11717A vulnerability exists where the caret ("^") character is im…5.3
- CVE-2019-11718Activity Stream can display content from sent from the Snipp…5.3
- CVE-2019-11719When importing a curve25519 private key in PKCS#8format with…
- CVE-2019-1172An information disclosure vulnerability exists in Azure Acti…4.3
- CVE-2019-11720Some unicode characters are incorrectly treated as whitespac…6.1
Are you affected by CVE-2019-11715?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
