EUVD-2019-3378
Insufficient vetting of parameters passed with the Prompt:Open IPC message between child and parent processes can result in the non-sandboxed parent process opening web content chosen by a compromised child process. When combined with additional vulnerabilities this could result in executing arbitrary code on the user's computer. This vulnerability affects Firefox ESR < 60.7.2, Firefox < 67.0.4, and Thunderbird < 60.7.2.
- EUVD state
- Present in the current official mapping
- Known exploitation
- Recorded by ENISA since 23 May 2022. Evidence sources: cisa_kev.
- ENISA score
- 10.0 · CVSS 3.1
- Advisory evidence
- 15 linked advisory records
Only statements that explicitly mention a fix, patch, update, workaround or mitigation are shown here.
- csaf_redhat · RHSA-2019:1624Red Hat Security Advisory: thunderbird security update
- csaf_redhat · RHSA-2019:1696Red Hat Security Advisory: firefox security update
- csaf_suse · SUSE-SU-2019:1684-1Security update for MozillaFirefox
- csaf_suse · SUSE-SU-2019:14124-1Security update for MozillaFirefox
- csaf_redhat · RHSA-2019:1623Red Hat Security Advisory: thunderbird security update
- csaf_opensuse · openSUSE-SU-2019:1606-1Security update for MozillaThunderbird
- csaf_redhat · RHSA-2019:1604Red Hat Security Advisory: firefox security update
- csaf_redhat · RHSA-2019:1603Red Hat Security Advisory: firefox security update
- csaf_opensuse · openSUSE-SU-2019:1595-1Security update for MozillaFirefox
- csaf_suse · SUSE-SU-2019:1683-1Security update for MozillaThunderbird
- csaf_opensuse · openSUSE-SU-2019:1664-1Security update for MozillaThunderbird
- csaf_redhat · RHSA-2019:1626Red Hat Security Advisory: thunderbird security update
- csaf_suse · SUSE-SU-2019:1682-1Security update for MozillaFirefox
