CVE-2019-11695 PUBLISHED

A custom cursor defined by scripting on a site can position itself over the addressbar to spoof the actual cursor when it should not be allowed outside of the primary web content area. This could be used by a malicious site to trick users into clicking on permission prompts, doorhanger notifications, or other buttons inadvertently if the location is spoofed over the user interface. This vulnerability affects Firefox < 67.

EPSS 0.19% · 40.2th percentile

Risk Scores

EPSS Score
0.19%
40.2th percentile

Affected Products

VendorProductVersions
Ubuntu:18.04:LTSmozjs520, 52.3.1-0ubuntu3, 52.3.1-7fakesync1
Ubuntu:18.04:LTSfirefox60.0+build2-0ubuntu1, 60.0.1+build2-0ubuntu0.18.04.1, 60.0.2+build1-0ubuntu0.18.04.1
Ubuntu:18.04:LTSmozjs380, 38.8.0~repack1-0ubuntu1, 38.8.0~repack1-0ubuntu3
Ubuntu:16.04:LTSfirefox57.0.3+build1-0ubuntu0.16.04.1, 57.0.4+build1-0ubuntu0.16.04.1, 58.0+build6-0ubuntu0.16.04.1
Ubuntu:20.04:LTSmozjs520, 52.9.1-1build1, 52.9.1-1ubuntu3

Timeline

References

Open in Interactive Console →