Cross-origin images can be read from a canvas element in violation of the same-origin policy using the transferFromImageBitmap method. *Note: This only affects Firefox 65. Previous versions are unaffected.*. This vulnerability affects Firefox < 65.0.1.
http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00002.html
http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00029.html
http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00084.html
https://access.redhat.com/errata/RHSA-2019:1265
https://access.redhat.com/errata/RHSA-2019:1267
https://access.redhat.com/errata/RHSA-2019:1269
https://access.redhat.com/errata/RHSA-2019:1308
https://access.redhat.com/errata/RHSA-2019:1309
https://access.redhat.com/errata/RHSA-2019:1310
https://bugzilla.mozilla.org/show_bug.cgi?id=1526218
https://lists.debian.org/debian-lts-announce/2019/05/msg00032.html
https://lists.debian.org/debian-lts-announce/2019/05/msg00038.html
https://seclists.org/bugtraq/2019/May/56
https://seclists.org/bugtraq/2019/May/59
https://seclists.org/bugtraq/2019/May/67
https://usn.ubuntu.com/3997-1/
https://www.debian.org/security/2019/dsa-4448
Source: MITRE
Published: 2019-04-26
Updated: 2019-06-10
Type: CWE-200
Base Score: 4.3
Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N
Impact Score: 2.9
Exploitability Score: 8.6
Severity: MEDIUM
Base Score: 4.3
Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
Impact Score: 1.4
Exploitability Score: 2.8
Severity: MEDIUM
OR
ID | Name | Product | Family | Severity |
---|---|---|---|---|
145688 | CentOS 8 : firefox (CESA-2019:1269) | Nessus | CentOS Local Security Checks | high |
145630 | CentOS 8 : thunderbird (CESA-2019:1308) | Nessus | CentOS Local Security Checks | high |
128698 | NewStart CGSL MAIN 4.06 : thunderbird Multiple Vulnerabilities (NS-SA-2019-0178) | Nessus | NewStart CGSL Local Security Checks | critical |
128691 | NewStart CGSL MAIN 4.06 : firefox Multiple Vulnerabilities (NS-SA-2019-0175) | Nessus | NewStart CGSL Local Security Checks | critical |
127589 | Oracle Linux 8 : thunderbird (ELSA-2019-1308) | Nessus | Oracle Linux Local Security Checks | high |
127587 | Oracle Linux 8 : firefox (ELSA-2019-1269) | Nessus | Oracle Linux Local Security Checks | high |
127459 | NewStart CGSL MAIN 4.05 : thunderbird Multiple Vulnerabilities (NS-SA-2019-0169) | Nessus | NewStart CGSL Local Security Checks | high |
127455 | NewStart CGSL MAIN 4.05 : firefox Multiple Vulnerabilities (NS-SA-2019-0167) | Nessus | NewStart CGSL Local Security Checks | high |
127439 | NewStart CGSL CORE 5.04 / MAIN 5.04 : firefox Multiple Vulnerabilities (NS-SA-2019-0159) | Nessus | NewStart CGSL Local Security Checks | high |
127438 | NewStart CGSL CORE 5.04 / MAIN 5.04 : thunderbird Multiple Vulnerabilities (NS-SA-2019-0158) | Nessus | NewStart CGSL Local Security Checks | high |
127305 | NewStart CGSL CORE 5.05 / MAIN 5.05 : thunderbird Multiple Vulnerabilities (NS-SA-2019-0088) | Nessus | NewStart CGSL Local Security Checks | high |
127304 | NewStart CGSL CORE 5.05 / MAIN 5.05 : firefox Multiple Vulnerabilities (NS-SA-2019-0087) | Nessus | NewStart CGSL Local Security Checks | high |
125901 | Amazon Linux 2 : thunderbird (ALAS-2019-1229) | Nessus | Amazon Linux Local Security Checks | high |
125809 | openSUSE Security Update : MozillaFirefox (openSUSE-2019-1534) | Nessus | SuSE Local Security Checks | high |
125803 | CentOS 6 : thunderbird (CESA-2019:1310) | Nessus | CentOS Local Security Checks | high |
125802 | CentOS 7 : thunderbird (CESA-2019:1309) | Nessus | CentOS Local Security Checks | high |
125716 | Scientific Linux Security Update : thunderbird on SL7.x x86_64 (20190604) | Nessus | Scientific Linux Local Security Checks | high |
125715 | Scientific Linux Security Update : thunderbird on SL6.x i386/x86_64 (20190604) | Nessus | Scientific Linux Local Security Checks | high |
125692 | RHEL 6 : thunderbird (RHSA-2019:1310) | Nessus | Red Hat Local Security Checks | high |
125691 | RHEL 7 : thunderbird (RHSA-2019:1309) | Nessus | Red Hat Local Security Checks | high |
125690 | RHEL 8 : thunderbird (RHSA-2019:1308) | Nessus | Red Hat Local Security Checks | high |
125689 | Oracle Linux 6 : thunderbird (ELSA-2019-1310) | Nessus | Oracle Linux Local Security Checks | high |
125688 | Oracle Linux 7 : thunderbird (ELSA-2019-1309) | Nessus | Oracle Linux Local Security Checks | high |
125669 | openSUSE Security Update : MozillaThunderbird (openSUSE-2019-1484) | Nessus | SuSE Local Security Checks | high |
125554 | CentOS 6 : firefox (CESA-2019:1267) | Nessus | CentOS Local Security Checks | high |
125553 | CentOS 7 : firefox (CESA-2019:1265) | Nessus | CentOS Local Security Checks | high |
125545 | Ubuntu 16.04 LTS / 18.04 LTS / 18.10 / 19.04 : Thunderbird vulnerabilities (USN-3997-1) | Nessus | Ubuntu Local Security Checks | high |
125449 | Scientific Linux Security Update : firefox on SL7.x x86_64 (20190524) | Nessus | Scientific Linux Local Security Checks | high |
125447 | Scientific Linux Security Update : firefox on SL6.x i386/x86_64 (20190523) | Nessus | Scientific Linux Local Security Checks | high |
125444 | Oracle Linux 6 : firefox (ELSA-2019-1267) | Nessus | Oracle Linux Local Security Checks | high |
125443 | Oracle Linux 7 : firefox (ELSA-2019-1265) | Nessus | Oracle Linux Local Security Checks | high |
125415 | Debian DSA-4451-1 : thunderbird - security update | Nessus | Debian Local Security Checks | high |
125412 | Debian DLA-1806-1 : thunderbird security update | Nessus | Debian Local Security Checks | high |
125385 | RHEL 8 : firefox (RHSA-2019:1269) | Nessus | Red Hat Local Security Checks | high |
125383 | RHEL 6 : firefox (RHSA-2019:1267) | Nessus | Red Hat Local Security Checks | high |
125382 | RHEL 7 : firefox (RHSA-2019:1265) | Nessus | Red Hat Local Security Checks | high |
125374 | Debian DLA-1800-1 : firefox-esr security update | Nessus | Debian Local Security Checks | high |
125363 | Mozilla Firefox ESR < 60.7 | Nessus | Windows | high |
125362 | Mozilla Firefox ESR < 60.7 | Nessus | MacOS X Local Security Checks | high |
125359 | Mozilla Thunderbird < 60.7 | Nessus | Windows | high |
125358 | Mozilla Thunderbird < 60.7 | Nessus | MacOS X Local Security Checks | high |
125343 | Debian DSA-4448-1 : firefox-esr - security update | Nessus | Debian Local Security Checks | high |
700733 | Mozilla Firefox ESR < 60.7 Multiple Vulnerabilities | Nessus Network Monitor | Web Clients | critical |
700486 | Mozilla Firefox < 65.0.1 Multiple Vulnerabilities | Nessus Network Monitor | Web Clients | medium |
122233 | Mozilla Firefox < 65.0.1 | Nessus | Windows | medium |
122232 | Mozilla Firefox < 65.0.1 | Nessus | MacOS X Local Security Checks | medium |
122165 | FreeBSD : mozilla -- multiple vulnerabilities (18211552-f650-4d86-ba4f-e6d5cbfcdbeb) | Nessus | FreeBSD Local Security Checks | medium |
700742 | Mozilla Thunderbird < 60.7 Multiple Vulnerabilities | Nessus Network Monitor | SMTP Clients | high |