Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2018-12399

Опубликовано: 28 фев. 2019
Источник: debian
EPSS Низкий

Описание

When a new protocol handler is registered, the API accepts a title argument which can be used to mislead users about which domain is registering the new protocol. This may result in the user approving a protocol handler that they otherwise would not have. This vulnerability affects Firefox < 63.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
firefoxfixed63.0-1package

Примечания

  • https://www.mozilla.org/en-US/security/advisories/mfsa2018-26/#CVE-2018-12399

EPSS

Процентиль: 61%
0.00407
Низкий

Связанные уязвимости

CVSS3: 4.3
ubuntu
почти 7 лет назад

When a new protocol handler is registered, the API accepts a title argument which can be used to mislead users about which domain is registering the new protocol. This may result in the user approving a protocol handler that they otherwise would not have. This vulnerability affects Firefox < 63.

CVSS3: 4.3
redhat
больше 7 лет назад

When a new protocol handler is registered, the API accepts a title argument which can be used to mislead users about which domain is registering the new protocol. This may result in the user approving a protocol handler that they otherwise would not have. This vulnerability affects Firefox < 63.

CVSS3: 4.3
nvd
почти 7 лет назад

When a new protocol handler is registered, the API accepts a title argument which can be used to mislead users about which domain is registering the new protocol. This may result in the user approving a protocol handler that they otherwise would not have. This vulnerability affects Firefox < 63.

CVSS3: 4.3
github
больше 3 лет назад

When a new protocol handler is registered, the API accepts a title argument which can be used to mislead users about which domain is registering the new protocol. This may result in the user approving a protocol handler that they otherwise would not have. This vulnerability affects Firefox < 63.

CVSS3: 4.3
fstec
больше 7 лет назад

Уязвимость компонента API браузера Firefox, позволяющая нарушителю подменить пользовательский интерфейс

EPSS

Процентиль: 61%
0.00407
Низкий