Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-6h2f-xfhj-5wr4

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The structured-clone implementation in Mozilla Firefox before 34.0 and SeaMonkey before 2.31 does not properly interact with XrayWrapper property filtering, which allows remote attackers to bypass intended DOM object restrictions by leveraging property availability after XrayWrapper removal.

The structured-clone implementation in Mozilla Firefox before 34.0 and SeaMonkey before 2.31 does not properly interact with XrayWrapper property filtering, which allows remote attackers to bypass intended DOM object restrictions by leveraging property availability after XrayWrapper removal.

EPSS

Процентиль: 60%
0.01018
Низкий

Дефекты

CWE-284

Связанные уязвимости

ubuntu
больше 11 лет назад

The structured-clone implementation in Mozilla Firefox before 34.0 and SeaMonkey before 2.31 does not properly interact with XrayWrapper property filtering, which allows remote attackers to bypass intended DOM object restrictions by leveraging property availability after XrayWrapper removal.

redhat
больше 11 лет назад

The structured-clone implementation in Mozilla Firefox before 34.0 and SeaMonkey before 2.31 does not properly interact with XrayWrapper property filtering, which allows remote attackers to bypass intended DOM object restrictions by leveraging property availability after XrayWrapper removal.

nvd
больше 11 лет назад

The structured-clone implementation in Mozilla Firefox before 34.0 and SeaMonkey before 2.31 does not properly interact with XrayWrapper property filtering, which allows remote attackers to bypass intended DOM object restrictions by leveraging property availability after XrayWrapper removal.

debian
больше 11 лет назад

The structured-clone implementation in Mozilla Firefox before 34.0 and ...

EPSS

Процентиль: 60%
0.01018
Низкий

Дефекты

CWE-284