CVE-2019-11695
Dashboard / Vulnerabilities / CVE-2019-11695
CVE-2019-11695
Published: 23 Jul 2019Last Modified: 10 Mar 2026
Summary:
Details: A custom cursor defined by scripting on a site can position itself over the addressbar to spoof the actual cursor when it should not be allowed outside of the primary web content area. This could be used by a malicious site to trick users into clicking on permission prompts, doorhanger notifications, or other buttons inadvertently if the location is spoofed over the user interface. This vulnerability affects Firefox < 67.
References: , https://www.mozilla.org/security/advisories/mfsa2019-13/, https://bugzilla.mozilla.org/show_bug.cgi?id=1445844
Affected packages
Package
Name:
Purl:
Affected ranges
Type: N/A
Events:
Introduced- None
Fixed -None
Affected versions
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
