CVE Database
/

CVE-2019-11763

Back to search

CVE-2019-11763

Published: Jan 8, 2020

Modified: Aug 4, 2024

PUBLISHED

Description

Failure to correctly handle null bytes when processing HTML entities resulted in Firefox incorrectly parsing these entities. This could have led to HTML comment text being treated as HTML which could have led to XSS in a web application under certain conditions. It could have also led to HTML entities being masked from filters - enabling the use of entities to mask the actual characters of interest from filters. This vulnerability affects Firefox < 70, Thunderbird < 68.2, and Firefox ESR < 68.2.

VendorProductVersions

Mozilla

Firefox

affected
before 70

Mozilla

Thunderbird

affected
before 68.2

Mozilla

Firefox ESR

affected
before 68.2

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now