Free and open-source vulnerability scanner

Mageni eases for you the vulnerability scanning, assessment, and management process. It is free and open-source.

Install Now

Available for macOS, Windows, and Linux

App screenshot

Mozilla Firefox Security Updates(mfsa_2019-06_2019-08)-MAC OS X

Information

Severity

Severity

High

Family

Family

General

CVSSv2 Base

CVSSv2 Base

7.5

CVSSv2 Vector

CVSSv2 Vector

AV:N/AC:L/Au:N/C:P/I:P/A:P

Solution Type

Solution Type

Vendor Patch

Created

Created

5 years ago

Modified

Modified

4 years ago

Summary

This host is installed with Mozilla Firefox and is prone to multiple vulnerabilities.

Insight

Insight

Multiple flaws exists due to, - An integer overflow error in Skia. - An use-after-free error when removing in-use DOM elements. - Multiple type confusion errors through on-stack replacement with IonMonkey. - An error in IonMonkey just-in-time (JIT) compiler. - An improper bounds checks when Spectre mitigations are disabled. - A type confusion error in IonMonkey JIT compiler. - An use-after-free error with SMIL animation controller. - Cross-origin theft of images with createImageBitmap. - An insufficient bounds checking of data during inter-process communication. - A memory read error in Chrome process. - Upgrade-Insecure-Requests incorrectly enforced for same-origin navigation. - Use of uninitialized memory in Prio library. - A vulnerability exists during authorization prompting for FTP transaction. - Text sent through FTP connection can be incorporated into alert messages. - WebRTC permissions can display incorrect origin with data: and blob: URLs. - An error in handling FTP modal alert error messages. - An error in Firefox Developer Tools through 'Copy as cURL'. - Memory safety bugs.

Affected Software

Affected Software

Mozilla Firefox version before 66 on MAC OS X.

Detection Method

Detection Method

Checks if a vulnerable version is present on the target host.

Solution

Solution

Upgrade to Mozilla Firefox version 66 or later. Please see the references for more information.