CVE-2019-9798 PUBLISHED

On Android systems, Firefox can load a library from APITRACE_LIB, which is writable by all users and applications. This could allow malicious third party applications to execute a man-in-the-middle attack if a malicious code was written to that location and loaded. *Note: This issue only affects Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 66.

EPSS 0.19% · 41.2th percentile

Risk Scores

EPSS Score
0.19%
41.2th percentile

Affected Products

VendorProductVersions
Ubuntu:20.04:LTSmozjs520, 52.9.1-1build1, 52.9.1-1ubuntu3
Ubuntu:18.04:LTSmozjs3838.8.0~repack1-0ubuntu4, 0, 38.8.0~repack1-0ubuntu1
Ubuntu:18.04:LTSmozjs520, 52.3.1-0ubuntu3, 52.3.1-7fakesync1

Timeline

References

Open in Interactive Console →