VDB

DEBIAN-CVE-2019-11763

DEBIAN-CVE-2019-11763 PUBLISHED CVSS 6.099999904632568 MEDIUM

Failure to correctly handle null bytes when processing HTML entities resulted in Firefox incorrectly parsing these entities. This could have led to HTML comment text being treated as HTML which could have led to XSS in a web application under certain conditions. It could have also led to HTML entities being masked from filters - enabling the use of entities to mask the actual characters of interest from filters. This vulnerability affects Firefox < 70, Thunderbird < 68.2, and Firefox ESR < 68.2.

Risk Scores

CVSS v3.1
6.099999904632568
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Affected Products

VendorProductVersions
Debian:11firefox-esr0, 0, 0
Debian:14firefox-esr0, 0, 0
Debian:12firefox-esr0, 0, 0
Debian:14thunderbird0, 0, 0
Debian:13thunderbird0, 0, 0
Debian:13firefox-esr0, 0, 0
Debian:12thunderbird0, 0, 0
Debian:11thunderbird0, 0, 0

Timeline

  • Jan 8, 2020 CVE Published
  • Apr 28, 2026 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›