CVE-2019-9801 PUBLISHED

Firefox will accept any registered Program ID as an external protocol handler and offer to launch this local application when given a matching URL on Windows operating systems. This should only happen if the program has specifically registered itself as a "URL Handler" in the Windows registry. *Note: This issue only affects Windows operating systems. Other operating systems are unaffected.*. This vulnerability affects Thunderbird < 60.6, Firefox ESR < 60.6, and Firefox < 66.

EPSS 0.38% · 59.4th percentile

Risk Scores

EPSS Score
0.38%
59.4th percentile

Affected Products

VendorProductVersions
Ubuntu:18.04:LTSmozjs380, 38.8.0~repack1-0ubuntu1, 38.8.0~repack1-0ubuntu3
Ubuntu:18.04:LTSmozjs5252.9.1-0ubuntu0.18.04.1, 0, 52.3.1-0ubuntu3
Ubuntu:20.04:LTSmozjs520, 52.9.1-1build1, 52.9.1-1ubuntu3

Timeline

References

Open in Interactive Console →