VDB
GCVE-110-MAGEIA-2020-27
GCVE-110-MAGEIA-2020-27
Advisory Published
When pasting a <style> tag from the clipboard into a rich text editor, the CSS
sanitizer incorrectly rewrites a @namespace rule. This could allow for
injection into certain types of websites resulting in data exfiltration
(CVE-2019-17016).
Due to a missing case handling object types, a type confusion vulnerability
could occur, resulting in a crash. We presume that with enough effort that it
could be exploited to run arbitrary code (CVE-2019-17017).
When pasting a <style> tag from the clipboard into a rich text editor, the CSS
sanitizer does not escape < and > characters. Because the resulting string is
pasted directly into the text node of the element this does not result in a
direct injection into the webpage; however, if a webpage subsequently copies
the node's innerHTML, assigning it to another innerHTML, this would result in
an XSS vulnerability. Two WYSIWYG editors were identified with this behavior,
more may exist (CVE-2019-17022).
Mozilla developers reported memory safety bugs present in Firefox ESR 68.3.
Some of these bugs showed evidence of memory corruption and we presume that
with enough effort some of these could have been exploited to run arbitrary
code (CVE-2019-17024).
Incorrect alias information in IonMonkey JIT compiler for setting array
elements could lead to a type confusion. We are aware of targeted attacks in
the wild abusing this flaw (CVE-2019-17026).
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| Mageia | perl | 0 (affected), 5.28.2-2.mga7 (unaffected) | — |
| Mageia | nss | 0 (affected), 3.49.0-1.mga7 (unaffected), 0 (affected), 3.49.0-1.mga7 (unaffected) | — |
| Mageia | firefox | 0 (affected), 68.4.1-1.mga7 (unaffected), 0 (affected), 68.4.1-1.mga7 (unaffected) | — |
| Mageia | firefox-l10n | 68.4.1-1.mga7 (unaffected), 0 (affected), 0 (affected), 68.4.1-1.mga7 (unaffected) | — |
References
Browse GCVE Records
75,974 records in the GCVE database · Updated August 5, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.