CVE-2019-9817: Mozilla Firefox
Medium severity, CVSS 5.3. EPSS: 0.8% chance of exploitation in the next 30 days.
Images from a different domain can be read using a canvas object in some circumstances. This could be used to steal image data from a different site in violation of same-origin policy. This vulnerability affects Thunderbird < 60.7, Firefox < 67, and Firefox ESR < 60.7.
Affected products
- Mozilla Firefox: before 67.0 (fixed in 67.0)
- Mozilla Firefox ESR: before 60.7 (fixed in 60.7)
- Mozilla Thunderbird: before 60.7 (fixed in 60.7)
Published 2019-07-23. Last modified 2026-06-17.