Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-65f9-wqxf-mh9r

Опубликовано: 27 сент. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 6.5

Описание

A compromised content process could have provided malicious data in a PathRecording resulting in an out-of-bounds write, leading to a potentially exploitable crash in a privileged process. This vulnerability affects Firefox < 118, Firefox ESR < 115.3, and Thunderbird < 115.3.

A compromised content process could have provided malicious data in a PathRecording resulting in an out-of-bounds write, leading to a potentially exploitable crash in a privileged process. This vulnerability affects Firefox < 118, Firefox ESR < 115.3, and Thunderbird < 115.3.

EPSS

Процентиль: 50%
0.00267
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-787

Связанные уязвимости

CVSS3: 6.5
ubuntu
больше 1 года назад

A compromised content process could have provided malicious data in a `PathRecording` resulting in an out-of-bounds write, leading to a potentially exploitable crash in a privileged process. This vulnerability affects Firefox < 118, Firefox ESR < 115.3, and Thunderbird < 115.3.

CVSS3: 6.5
redhat
больше 1 года назад

A compromised content process could have provided malicious data in a `PathRecording` resulting in an out-of-bounds write, leading to a potentially exploitable crash in a privileged process. This vulnerability affects Firefox < 118, Firefox ESR < 115.3, and Thunderbird < 115.3.

CVSS3: 6.5
nvd
больше 1 года назад

A compromised content process could have provided malicious data in a `PathRecording` resulting in an out-of-bounds write, leading to a potentially exploitable crash in a privileged process. This vulnerability affects Firefox < 118, Firefox ESR < 115.3, and Thunderbird < 115.3.

CVSS3: 6.5
debian
больше 1 года назад

A compromised content process could have provided malicious data in a ...

CVSS3: 6.5
fstec
больше 1 года назад

Уязвимость веб-браузеров Firefox ESR, Firefox и почтового клиента Thunderbird, связанная с записью за границами буфера, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 50%
0.00267
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-787