Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2021-29944

Опубликовано: 24 июн. 2021
Источник: debian
EPSS Низкий

Описание

Lack of escaping allowed HTML injection when a webpage was viewed in Reader View. While a Content Security Policy prevents direct code execution, HTML injection is still possible. *Note: This issue only affected Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 88.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
firefoxnot-affectedpackage

Примечания

  • https://www.mozilla.org/en-US/security/advisories/mfsa2021-16/#CVE-2021-29944

EPSS

Процентиль: 59%
0.00377
Низкий

Связанные уязвимости

CVSS3: 6.1
ubuntu
больше 4 лет назад

Lack of escaping allowed HTML injection when a webpage was viewed in Reader View. While a Content Security Policy prevents direct code execution, HTML injection is still possible. *Note: This issue only affected Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 88.

CVSS3: 6.1
nvd
больше 4 лет назад

Lack of escaping allowed HTML injection when a webpage was viewed in Reader View. While a Content Security Policy prevents direct code execution, HTML injection is still possible. *Note: This issue only affected Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 88.

github
больше 3 лет назад

Lack of escaping allowed HTML injection when a webpage was viewed in Reader View. While a Content Security Policy prevents direct code execution, HTML injection is still possible. *Note: This issue only affected Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 88.

EPSS

Процентиль: 59%
0.00377
Низкий