Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-63j5-535g-4392

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 8.3

Описание

As part of a winning Pwn2Own entry, a researcher demonstrated a sandbox escape by installing a malicious language pack and then opening a browser feature that used the compromised translation. This vulnerability affects Firefox ESR < 60.8, Firefox < 68, and Thunderbird < 60.8.

As part of a winning Pwn2Own entry, a researcher demonstrated a sandbox escape by installing a malicious language pack and then opening a browser feature that used the compromised translation. This vulnerability affects Firefox ESR < 60.8, Firefox < 68, and Thunderbird < 60.8.

EPSS

Процентиль: 72%
0.00733
Низкий

8.3 High

CVSS3

Дефекты

CWE-74

Связанные уязвимости

CVSS3: 8.3
ubuntu
больше 6 лет назад

As part of a winning Pwn2Own entry, a researcher demonstrated a sandbox escape by installing a malicious language pack and then opening a browser feature that used the compromised translation. This vulnerability affects Firefox ESR < 60.8, Firefox < 68, and Thunderbird < 60.8.

CVSS3: 7.5
redhat
больше 6 лет назад

As part of a winning Pwn2Own entry, a researcher demonstrated a sandbox escape by installing a malicious language pack and then opening a browser feature that used the compromised translation. This vulnerability affects Firefox ESR < 60.8, Firefox < 68, and Thunderbird < 60.8.

CVSS3: 8.3
nvd
больше 6 лет назад

As part of a winning Pwn2Own entry, a researcher demonstrated a sandbox escape by installing a malicious language pack and then opening a browser feature that used the compromised translation. This vulnerability affects Firefox ESR < 60.8, Firefox < 68, and Thunderbird < 60.8.

CVSS3: 8.3
debian
больше 6 лет назад

As part of a winning Pwn2Own entry, a researcher demonstrated a sandbo ...

CVSS3: 8.3
fstec
больше 6 лет назад

Уязвимость браузеров Firefox ESR, Firefox и почтового клиента Thunderbird, связанная с недостатками разграничения доступа, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 72%
0.00733
Низкий

8.3 High

CVSS3

Дефекты

CWE-74