CVE-2019-17014: Mozilla Firefox
High severity, CVSS 7.4. EPSS: 1.1% chance of exploitation in the next 30 days.
If an image had not loaded correctly (such as when it is not actually an image), it could be dragged and dropped cross-domain, resulting in a cross-origin information leak. This vulnerability affects Firefox < 71.
Affected products
- Mozilla Firefox: before 71.0 (fixed in 71.0)
Published 2020-01-08. Last modified 2026-06-17.