Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2022-31736

Опубликовано: 22 дек. 2022
Источник: debian
EPSS Низкий

Описание

A malicious website could have learned the size of a cross-origin resource that supported Range requests. This vulnerability affects Thunderbird < 91.10, Firefox < 101, and Firefox ESR < 91.10.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
firefoxfixed101.0-1package
firefox-esrfixed91.10.0esr-1package
thunderbirdfixed1:91.10.0-1package

Примечания

  • https://www.mozilla.org/en-US/security/advisories/mfsa2022-20/#CVE-2022-31736

  • https://www.mozilla.org/en-US/security/advisories/mfsa2022-21/#CVE-2022-31736

  • https://www.mozilla.org/en-US/security/advisories/mfsa2022-22/#CVE-2022-31736

EPSS

Процентиль: 39%
0.00171
Низкий

Связанные уязвимости

CVSS3: 9.8
ubuntu
больше 2 лет назад

A malicious website could have learned the size of a cross-origin resource that supported Range requests. This vulnerability affects Thunderbird < 91.10, Firefox < 101, and Firefox ESR < 91.10.

CVSS3: 9.8
redhat
около 3 лет назад

A malicious website could have learned the size of a cross-origin resource that supported Range requests. This vulnerability affects Thunderbird < 91.10, Firefox < 101, and Firefox ESR < 91.10.

CVSS3: 9.8
nvd
больше 2 лет назад

A malicious website could have learned the size of a cross-origin resource that supported Range requests. This vulnerability affects Thunderbird < 91.10, Firefox < 101, and Firefox ESR < 91.10.

CVSS3: 9.8
github
больше 2 лет назад

A malicious website could have learned the size of a cross-origin resource that supported Range requests. This vulnerability affects Thunderbird < 91.10, Firefox < 101, and Firefox ESR < 91.10.

CVSS3: 7.5
fstec
около 3 лет назад

Уязвимость реализации механизма CORS (Cross-Origin Resource Sharing) браузеров Firefox, Firefox ESR и почтового клиента Thunderbird, позволяющая нарушителю обойти ограничения безопасности

EPSS

Процентиль: 39%
0.00171
Низкий