CVE-2019-9807: Input Validation
Published Mar 19, 2019
·Updated
Last updated 24 July 2024
Other sources
When arbitrary text is sent over an FTP connection and a page reload is initiated, it is possible to create a modal alert message with this text as the content. This could potentially be used for social engineering attacks.
Affected Software
3 affected componentsFixes available
Mozilla Firefox<66
66
Mozilla Firefox<66.0
debian/firefox
138.0-1
Event History
Mar 19, 2019
CVE Published
12:00 AM
Apr 26, 2019
CVE Published
via MITRE·04:10 PM
Data Sourced
via MITRE·04:10 PM
DescriptionWeakness
Jan 11, 2024
Data Sourced
via Launchpad·11:33 PM
Description
Sep 16, 2024
Data Sourced
via Ubuntu·02:18 AM
RemedyDescriptionSeverityAffected Software
Mar 27, 2025
Data Sourced
via Debian·04:11 AM
DescriptionAffected Software
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
1
What is the vulnerability ID of this vulnerability?
The vulnerability ID is CVE-2019-9807.
2
What is the severity level of CVE-2019-9807?
CVE-2019-9807 has a severity level of medium (4.3).
3
How does CVE-2019-9807 affect Firefox?
CVE-2019-9807 affects Firefox versions prior to 66.
4
What can an attacker potentially do with CVE-2019-9807?
An attacker could potentially use CVE-2019-9807 for social engineering attacks by creating a modal alert message with arbitrary text.
5
Are there any remediation steps available for CVE-2019-9807?
Yes, upgrading to Firefox version 66 or later will fix the vulnerability.