Free and open-source vulnerability scanner
Mageni eases for you the vulnerability scanning, assessment, and management process. It is free and open-source.
Install NowAvailable for macOS, Windows, and Linux
Mozilla Firefox ESR Security Updates(mfsa_2019-25_2019-27)-Windows
Information
Severity
Severity
Family
Family
CVSSv2 Base
CVSSv2 Base
CVSSv2 Vector
CVSSv2 Vector
Solution Type
Solution Type
Created
Created
Modified
Modified
Summary
This host is installed with Mozilla Firefox ESR and is prone to multiple vulnerabilities.
Insight
Insight
Multiple flaws exists due to, - Logging-related command line parameters are not properly sanitized. - Multiple use-after-free errors. - A same-origin policy violation. - The Mozilla Maintenance Service does not guard against files being hardlinked to another file in the updates directory. - Privilege escalation with Mozilla Maintenance Service in custom Firefox installation location. - Sandbox escape through Firefox Sync - Navigation events were not fully adhering to the W3C's 'Navigation-Timing Level 2' draft specification in some instances for the unload event. - Persistence of WebRTC permissions in a third party context. - A vulnerability exists in WebRTC where malicious web content can use probing techniques on the getUserMedia API using constraints. - A type confusion vulnerability exists in Spidermonkey. - 'Forget about this site' removes sites from pre-loaded HSTS list. - Content Security Policy (CSP) bypass. - Memory safety bugs.
Affected Software
Affected Software
Mozilla Firefox ESR version before 68.1 on Windows.
Detection Method
Detection Method
Checks if a vulnerable version is present on the target host.
Solution
Solution
Upgrade to Mozilla Firefox ESR version 68.1 or later. Please see the references for more information.