Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-86vg-9cc8-8gmf

Опубликовано: 13 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Mozilla Firefox before 27.0 and SeaMonkey before 2.24 allow remote attackers to bypass the Same Origin Policy and obtain sensitive information by using an IFRAME element in conjunction with certain timing measurements involving the document.caretPositionFromPoint and document.elementFromPoint functions.

Mozilla Firefox before 27.0 and SeaMonkey before 2.24 allow remote attackers to bypass the Same Origin Policy and obtain sensitive information by using an IFRAME element in conjunction with certain timing measurements involving the document.caretPositionFromPoint and document.elementFromPoint functions.

EPSS

Процентиль: 51%
0.00277
Низкий

Дефекты

CWE-1021

Связанные уязвимости

ubuntu
больше 11 лет назад

Mozilla Firefox before 27.0 and SeaMonkey before 2.24 allow remote attackers to bypass the Same Origin Policy and obtain sensitive information by using an IFRAME element in conjunction with certain timing measurements involving the document.caretPositionFromPoint and document.elementFromPoint functions.

redhat
больше 11 лет назад

Mozilla Firefox before 27.0 and SeaMonkey before 2.24 allow remote attackers to bypass the Same Origin Policy and obtain sensitive information by using an IFRAME element in conjunction with certain timing measurements involving the document.caretPositionFromPoint and document.elementFromPoint functions.

nvd
больше 11 лет назад

Mozilla Firefox before 27.0 and SeaMonkey before 2.24 allow remote attackers to bypass the Same Origin Policy and obtain sensitive information by using an IFRAME element in conjunction with certain timing measurements involving the document.caretPositionFromPoint and document.elementFromPoint functions.

debian
больше 11 лет назад

Mozilla Firefox before 27.0 and SeaMonkey before 2.24 allow remote att ...

fstec
больше 11 лет назад

Уязвимость пакета программ Mozilla SeaMonkey, позволяющая злоумышленнику выполнить обход правил ограничения домена

EPSS

Процентиль: 51%
0.00277
Низкий

Дефекты

CWE-1021