CVE-2019-9797
3Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackepss 1.1%
exploitation probability
1.1%top 36% of all CVEs
observed exploitation
nono source reports it
Cross-origin images can be read in violation of the same-origin policy by exporting an image after using createImageBitmap to read the image and then rendering the resulting bitmap image within a canvas element. This vulnerability affects Firefox < 66.
Affected products
Mozilla · FirefoxReferences
http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00002.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-06/msg00029.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-06/msg00084.htmlhttps://access.redhat.com/errata/RHSA-2019:1265https://access.redhat.com/errata/RHSA-2019:1267https://access.redhat.com/errata/RHSA-2019:1269https://access.redhat.com/errata/RHSA-2019:1308https://access.redhat.com/errata/RHSA-2019:1309https://access.redhat.com/errata/RHSA-2019:1310https://bugzilla.mozilla.org/show_bug.cgi?id=1528909https://lists.debian.org/debian-lts-announce/2019/05/msg00032.htmlhttps://lists.debian.org/debian-lts-announce/2019/05/msg00038.html