Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-3q69-c555-hw23

Опубликовано: 13 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 8.2

Описание

Inside the JavaScript parser, a cast of an integer to a narrower type can result in data read from outside the buffer being parsed. This usually results in a non-exploitable crash, but can leak a limited amount of information from memory if it matches JavaScript identifier syntax. This vulnerability affects Firefox < 56.

Inside the JavaScript parser, a cast of an integer to a narrower type can result in data read from outside the buffer being parsed. This usually results in a non-exploitable crash, but can leak a limited amount of information from memory if it matches JavaScript identifier syntax. This vulnerability affects Firefox < 56.

EPSS

Процентиль: 74%
0.01597
Низкий

8.2 High

CVSS3

Дефекты

CWE-125

Связанные уязвимости

CVSS3: 8.2
ubuntu
около 8 лет назад

Inside the JavaScript parser, a cast of an integer to a narrower type can result in data read from outside the buffer being parsed. This usually results in a non-exploitable crash, but can leak a limited amount of information from memory if it matches JavaScript identifier syntax. This vulnerability affects Firefox < 56.

CVSS3: 8.2
nvd
около 8 лет назад

Inside the JavaScript parser, a cast of an integer to a narrower type can result in data read from outside the buffer being parsed. This usually results in a non-exploitable crash, but can leak a limited amount of information from memory if it matches JavaScript identifier syntax. This vulnerability affects Firefox < 56.

CVSS3: 8.2
debian
около 8 лет назад

Inside the JavaScript parser, a cast of an integer to a narrower type ...

CVSS3: 8.2
fstec
около 9 лет назад

Уязвимость синтаксического анализатора JavaScript браузера Mozilla Firefox, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации или вызвать отказ в обслуживании

EPSS

Процентиль: 74%
0.01597
Низкий

8.2 High

CVSS3

Дефекты

CWE-125