Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-3q69-c555-hw23

Опубликовано: 13 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 8.2

Описание

Inside the JavaScript parser, a cast of an integer to a narrower type can result in data read from outside the buffer being parsed. This usually results in a non-exploitable crash, but can leak a limited amount of information from memory if it matches JavaScript identifier syntax. This vulnerability affects Firefox < 56.

Inside the JavaScript parser, a cast of an integer to a narrower type can result in data read from outside the buffer being parsed. This usually results in a non-exploitable crash, but can leak a limited amount of information from memory if it matches JavaScript identifier syntax. This vulnerability affects Firefox < 56.

EPSS

Процентиль: 68%
0.00579
Низкий

8.2 High

CVSS3

Дефекты

CWE-125

Связанные уязвимости

CVSS3: 8.2
ubuntu
больше 7 лет назад

Inside the JavaScript parser, a cast of an integer to a narrower type can result in data read from outside the buffer being parsed. This usually results in a non-exploitable crash, but can leak a limited amount of information from memory if it matches JavaScript identifier syntax. This vulnerability affects Firefox < 56.

CVSS3: 8.2
nvd
больше 7 лет назад

Inside the JavaScript parser, a cast of an integer to a narrower type can result in data read from outside the buffer being parsed. This usually results in a non-exploitable crash, but can leak a limited amount of information from memory if it matches JavaScript identifier syntax. This vulnerability affects Firefox < 56.

CVSS3: 8.2
debian
больше 7 лет назад

Inside the JavaScript parser, a cast of an integer to a narrower type ...

CVSS3: 8.2
fstec
больше 8 лет назад

Уязвимость синтаксического анализатора JavaScript браузера Mozilla Firefox, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации или вызвать отказ в обслуживании

EPSS

Процентиль: 68%
0.00579
Низкий

8.2 High

CVSS3

Дефекты

CWE-125