LiveActive security incident?Get immediate response
CVE archive

July 2019

Browse CVE records published in July 2019, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 50 of 1520 matching CVEs · Page 21 of 31.

Unknown · CVSS Not scored

CVE-2019-12174: hide.me before 2.4.4 on macOS suffers from a privilege escalation vulnerability in the connectWithExecutabl...

hide.me before 2.4.4 on macOS suffers from a privilege escalation vulnerability in the connectWithExecutablePath:configFilePath:configFileName method of the me_hide_vpnhelper.Helper class in the me.hide.vpnhelper macOS privilege helper tool. This method takes user-supplied input and can be used to escalate privileges, as well as obtain the ability to run any application on the system in the root context.

Published Jul 8, 2019 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2019-12000: HPE has found a potential Remote Access Restriction Bypass in HPE MSE Msg Gw application E-LTU prior to ver...

HPE has found a potential Remote Access Restriction Bypass in HPE MSE Msg Gw application E-LTU prior to version 3.2 when HTTPS is used between the USSD and an external USSD service logic application. Update to version 3.2 and update the HTTPS configuration as described in the HPE MSE Messaging Gateway Configuration and Operations Guide.

Published Jul 17, 2020 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2019-11989: A security vulnerability in HPE IceWall SSO Agent Option and IceWall MFA (Agent module ) could be exploited...

A security vulnerability in HPE IceWall SSO Agent Option and IceWall MFA (Agent module ) could be exploited remotely to cause a denial of service. The versions and platforms of Agent Option modules that are impacted are as follows: 10.0 for Apache 2.2 on RHEL 5 and 6, 10.0 for Apache 2.4 on RHEL 7, 10.0 for Apache 2.4 on HP-UX 11i v3, 10.0 for IIS on Windows, 11.0 for Apache 2.4 on RHEL 7, MFA Proxy 4.0 (Agent module only) for Apache 2.4 on RHEL 7.

Published Jul 19, 2019 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2019-11991: HPE has identified a vulnerability in HPE 3PAR Service Processor (SP) version 4.1 through 4.4.

HPE has identified a vulnerability in HPE 3PAR Service Processor (SP) version 4.1 through 4.4. HPE 3PAR Service Processor (SP) version 4.1 through 4.4 has a remote information disclosure vulnerability which can allow for the disruption of the confidentiality, integrity and availability of the Service Processor and any managed 3PAR arrays.

Published Jul 9, 2019 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2019-11990: Security vulnerabilities in HPE UIoT versions 1.6, 1.5, 1.4.2, 1.4.1, 1.4.0, and 1.2.4.2 could allow unauth...

Security vulnerabilities in HPE UIoT versions 1.6, 1.5, 1.4.2, 1.4.1, 1.4.0, and 1.2.4.2 could allow unauthorized remote access and access to sensitive data. HPE has addressed this issue in HPE UIoT: * For customers with release UIoT 1.6, fixes are made available with 1.6 RP603 * For customers with release UIoT 1.5, fixes are made available with 1.5 RP503 HF3 * For customers with release older than 1.5, such as 1.4.0, 1.4.1, 1.4.2 and 1.2.4.2, the resolution will be to upgrade to 1.5 RP503 HF3 or 1.6 RP603 Customers are requested to upgrade to the updated versions or contact HPE support for further assistance.

Published Jul 19, 2019 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2019-11772: In Eclipse OpenJ9 prior to 0.15, the String.getBytes(int, int, byte[], int) method does not verify that the...

In Eclipse OpenJ9 prior to 0.15, the String.getBytes(int, int, byte[], int) method does not verify that the provided byte array is non-null nor that the provided index is in bounds when compiled by the JIT. This allows arbitrary writes to any 32-bit address or beyond the end of a byte array within Java code run under a SecurityManager.

Published Jul 17, 2019 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2019-11775: All builds of Eclipse OpenJ9 prior to 0.15 contain a bug where the loop versioner may fail to privatize a v...

All builds of Eclipse OpenJ9 prior to 0.15 contain a bug where the loop versioner may fail to privatize a value that is pulled out of the loop by versioning - for example if there is a condition that is moved out of the loop that reads a field we may not privatize the value of that field in the modified copy of the loop allowing the test to see one value of the field and subsequently the loop to see a modified field value without retesting the condition moved out of the loop. This can lead to a variety of different issues but read out of array bounds is one major consequence of these problems.

Published Jul 30, 2019 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2019-11730: A vulnerability exists where if a user opens a locally saved HTML file, this file can use file: URIs to acc...

A vulnerability exists where if a user opens a locally saved HTML file, this file can use file: URIs to access other files in the same directory or sub-directories if the names are known or guessed. The Fetch API can then be used to read the contents of any files stored in these directories and they may uploaded to a server. It was demonstrated that in combination with a popular Android messaging app, if a malicious HTML attachment is sent to a user and they opened that attachment in Firefox, due to that app's predictable pattern for locally-saved file names, it is possible to read attachments the victim received from other correspondents. This vulnerability affects Firefox ESR < 60.8, Firefox < 68, and Thunderbird < 60.8.

Published Jul 23, 2019 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2019-11696: Files with the .JNLP extension used for "Java web start" applications are not treated as executable content...

Files with the .JNLP extension used for "Java web start" applications are not treated as executable content for download prompts even though they can be executed if Java is installed on the local system. This could allow users to mistakenly launch an executable binary locally. This vulnerability affects Firefox < 67.

Published Jul 23, 2019 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2019-11723: A vulnerability exists during the installation of add-ons where the initial fetch ignored the origin attrib...

A vulnerability exists during the installation of add-ons where the initial fetch ignored the origin attributes of the browsing context. This could leak cookies in private browsing mode or across different "containers" for people who use the Firefox Multi-Account Containers Web Extension. This vulnerability affects Firefox < 68.

Published Jul 23, 2019 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2019-11727: A vulnerability exists where it possible to force Network Security Services (NSS) to sign CertificateVerify...

A vulnerability exists where it possible to force Network Security Services (NSS) to sign CertificateVerify with PKCS#1 v1.5 signatures when those are the only ones advertised by server in CertificateRequest in TLS 1.3. PKCS#1 v1.5 signatures should not be used for TLS 1.3 messages. This vulnerability affects Firefox < 68.

Published Jul 23, 2019 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2019-11694: A vulnerability exists in the Windows sandbox where an uninitialized value in memory can be leaked to a ren...

A vulnerability exists in the Windows sandbox where an uninitialized value in memory can be leaked to a renderer from a broker when making a call to access an otherwise unavailable file. This results in the potential leaking of information stored at that memory location. *Note: this issue only occurs on Windows. Other operating systems are unaffected.*. This vulnerability affects Thunderbird < 60.7, Firefox < 67, and Firefox ESR < 60.7.

Published Jul 23, 2019 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2019-11709: Mozilla developers and community members reported memory safety bugs present in Firefox 67 and Firefox ESR...

Mozilla developers and community members reported memory safety bugs present in Firefox 67 and Firefox ESR 60.7. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firefox ESR < 60.8, Firefox < 68, and Thunderbird < 60.8.

Published Jul 23, 2019 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2019-11695: A custom cursor defined by scripting on a site can position itself over the addressbar to spoof the actual...

A custom cursor defined by scripting on a site can position itself over the addressbar to spoof the actual cursor when it should not be allowed outside of the primary web content area. This could be used by a malicious site to trick users into clicking on permission prompts, doorhanger notifications, or other buttons inadvertently if the location is spoofed over the user interface. This vulnerability affects Firefox < 67.

Published Jul 23, 2019 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2019-11716: Until explicitly accessed by script, window.globalThis is not enumerable and, as a result, is not visible t...

Until explicitly accessed by script, window.globalThis is not enumerable and, as a result, is not visible to code such as Object.getOwnPropertyNames(window). Sites that deploy a sandboxing that depends on enumerating and freezing access to the window object may miss this, allowing their sandboxes to be bypassed. This vulnerability affects Firefox < 68.

Published Jul 23, 2019 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2019-11698: If a crafted hyperlink is dragged and dropped to the bookmark bar or sidebar and the resulting bookmark is...

If a crafted hyperlink is dragged and dropped to the bookmark bar or sidebar and the resulting bookmark is subsequently dragged and dropped into the web content area, an arbitrary query of a user's browser history can be run and transmitted to the content page via drop event data. This allows for the theft of browser history by a malicious site. This vulnerability affects Thunderbird < 60.7, Firefox < 67, and Firefox ESR < 60.7.

Published Jul 23, 2019 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2019-11711: When an inner window is reused, it does not consider the use of document.domain for cross-origin protections.

When an inner window is reused, it does not consider the use of document.domain for cross-origin protections. If pages on different subdomains ever cooperatively use document.domain, then either page can abuse this to inject script into arbitrary pages on the other subdomain, even those that did not use document.domain to relax their origin security. This vulnerability affects Firefox ESR < 60.8, Firefox < 68, and Thunderbird < 60.8.

Published Jul 23, 2019 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2019-11701: The default webcal: protocol handler will load a web site vulnerable to cross-site scripting (XSS) attacks.

The default webcal: protocol handler will load a web site vulnerable to cross-site scripting (XSS) attacks. This default was left in place as a legacy feature and has now been removed. *Note: this issue only affects users with an account on the vulnerable service. Other users are unaffected.*. This vulnerability affects Firefox < 67.

Published Jul 23, 2019 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2019-11718: Activity Stream can display content from sent from the Snippet Service website.

Activity Stream can display content from sent from the Snippet Service website. This content is written to innerHTML on the Activity Stream page without sanitization, allowing for a potential access to other information available to the Activity Stream, such as browsing history, if the Snipper Service were compromised. This vulnerability affects Firefox < 68.

Published Jul 23, 2019 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2019-11725: When a user navigates to site marked as unsafe by the Safebrowsing API, warning messages are displayed and...

When a user navigates to site marked as unsafe by the Safebrowsing API, warning messages are displayed and navigation is interrupted but resources from the same site loaded through websockets are not blocked, leading to the loading of unsafe resources and bypassing safebrowsing protections. This vulnerability affects Firefox < 68.

Published Jul 23, 2019 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2019-11697: If the ALT and "a" keys are pressed when users receive an extension installation prompt, the extension will...

If the ALT and "a" keys are pressed when users receive an extension installation prompt, the extension will be installed without the install prompt delay that keeps the prompt visible in order for users to accept or decline the installation. A malicious web page could use this with spoofing on the page to trick users into installing a malicious extension. This vulnerability affects Firefox < 67.

Published Jul 23, 2019 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2019-11702: A hyperlink using protocols associated with Internet Explorer, such as IE.HTTP:, can be used to open local...

A hyperlink using protocols associated with Internet Explorer, such as IE.HTTP:, can be used to open local files at a known location with Internet Explorer if a user approves execution when prompted. *Note: this issue only occurs on Windows. Other operating systems are unaffected.*. This vulnerability affects Firefox < 67.0.2.

Published Jul 23, 2019 · Updated Aug 4, 2024