AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2019-11738

MEDIUM · CVSS 6.3 EPSS 1.45%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2019-09-27 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CVE
CVE-2019-11738
Severity
MEDIUM
CVSS
6.3
EPSS
1.45%
Firefox Java

Original NVD Description

If a Content Security Policy (CSP) directive is defined that uses a hash-based source that takes the empty string as input, execution of any javascript: URIs will be allowed. This could allow for malicious JavaScript content to be run, bypassing CSP permissions. This vulnerability affects Firefox < 69 and Firefox ESR < 68.1.

Related CVEs

Other vulnerabilities affecting the same vendor(s)