CVE-2019-9802 describes a memory reading vulnerability in Firefox versions prior to 66. An attacker could compromise a sandbox content process, initiate an FTP download, and then manipulate a child process to render downloaded data with an arbitrary file length. This bypasses sandbox protections, allowing for a potential memory read of adjacent sensitive data from the privileged Chrome process. The vulnerability has a CVSS score of 7.5 (HIGH), indicating a network-based attack with low complexity and high confidentiality impact. There is no known active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 66.0CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:* | ||
< 66CPE match | cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.