Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-8cc8-674c-8354

Опубликовано: 29 апр. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

The Script.prototype.freeze/thaw functionality in Mozilla 1.4 and earlier allows attackers to execute native methods by modifying the string used as input to the script.thaw JavaScript function, which is then deserialized and executed.

The Script.prototype.freeze/thaw functionality in Mozilla 1.4 and earlier allows attackers to execute native methods by modifying the string used as input to the script.thaw JavaScript function, which is then deserialized and executed.

EPSS

Процентиль: 78%
0.01149
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-502

Связанные уязвимости

CVSS3: 9.8
nvd
почти 22 года назад

The Script.prototype.freeze/thaw functionality in Mozilla 1.4 and earlier allows attackers to execute native methods by modifying the string used as input to the script.thaw JavaScript function, which is then deserialized and executed.

CVSS3: 9.8
debian
почти 22 года назад

The Script.prototype.freeze/thaw functionality in Mozilla 1.4 and earl ...

EPSS

Процентиль: 78%
0.01149
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-502