Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2jc3-9523-wwmj

Опубликовано: 01 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The Javascript SVG support in Opera before 9.10 does not properly validate object types in a createSVGTransformFromMatrix request, which allows remote attackers to execute arbitrary code via JavaScript code that uses an invalid object in this request that causes a controlled pointer to be referenced during the virtual function call.

The Javascript SVG support in Opera before 9.10 does not properly validate object types in a createSVGTransformFromMatrix request, which allows remote attackers to execute arbitrary code via JavaScript code that uses an invalid object in this request that causes a controlled pointer to be referenced during the virtual function call.

EPSS

Процентиль: 93%
0.10076
Средний

Дефекты

CWE-94

Связанные уязвимости

nvd
около 19 лет назад

The Javascript SVG support in Opera before 9.10 does not properly validate object types in a createSVGTransformFromMatrix request, which allows remote attackers to execute arbitrary code via JavaScript code that uses an invalid object in this request that causes a controlled pointer to be referenced during the virtual function call.

EPSS

Процентиль: 93%
0.10076
Средний

Дефекты

CWE-94