CVE-2019-11699 (NVD)

2019-07-23

A malicious page can briefly cause the wrong name to be highlighted as the domain name in the addressbar during page navigations. This could result in user confusion of which site is currently loaded for spoofing attacks. This vulnerability affects Firefox < 67.

Products Firefox
Type Improper Input Validation (CWE-20)
First patch - None (likely due to unavailable code)
Links https://bugzilla.mozilla.org/show_bug.cgi?id=1528939
https://www.mozilla.org/security/advisories/mfsa2019-13/