Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-3hwq-9jq5-p7f9

Опубликовано: 14 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 6.5

Описание

uri.js in Google V8 before 5.1.281.26, as used in Google Chrome before 51.0.2704.63, uses an incorrect array type, which allows remote attackers to obtain sensitive information by calling the decodeURI function and leveraging "type confusion."

uri.js in Google V8 before 5.1.281.26, as used in Google Chrome before 51.0.2704.63, uses an incorrect array type, which allows remote attackers to obtain sensitive information by calling the decodeURI function and leveraging "type confusion."

EPSS

Процентиль: 93%
0.09832
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-200

Связанные уязвимости

CVSS3: 6.5
ubuntu
больше 9 лет назад

uri.js in Google V8 before 5.1.281.26, as used in Google Chrome before 51.0.2704.63, uses an incorrect array type, which allows remote attackers to obtain sensitive information by calling the decodeURI function and leveraging "type confusion."

redhat
больше 9 лет назад

uri.js in Google V8 before 5.1.281.26, as used in Google Chrome before 51.0.2704.63, uses an incorrect array type, which allows remote attackers to obtain sensitive information by calling the decodeURI function and leveraging "type confusion."

CVSS3: 6.5
nvd
больше 9 лет назад

uri.js in Google V8 before 5.1.281.26, as used in Google Chrome before 51.0.2704.63, uses an incorrect array type, which allows remote attackers to obtain sensitive information by calling the decodeURI function and leveraging "type confusion."

CVSS3: 6.5
debian
больше 9 лет назад

uri.js in Google V8 before 5.1.281.26, as used in Google Chrome before ...

fstec
больше 9 лет назад

Уязвимость браузерного ядра V8, позволяющая нарушителю получить конфиденциальную информацию

EPSS

Процентиль: 93%
0.09832
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-200