Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9mvw-9c9q-7cmm

Опубликовано: 09 дек. 2021
Источник: github
Github: Не прошло ревью
CVSS3: 4.3

Описание

By misusing a race in our notification code, an attacker could have forcefully hidden the notification for pages that had received full screen and pointer lock access, which could have been used for spoofing attacks. This vulnerability affects Thunderbird < 91.4.0, Firefox ESR < 91.4.0, and Firefox < 95.

By misusing a race in our notification code, an attacker could have forcefully hidden the notification for pages that had received full screen and pointer lock access, which could have been used for spoofing attacks. This vulnerability affects Thunderbird < 91.4.0, Firefox ESR < 91.4.0, and Firefox < 95.

EPSS

Процентиль: 51%
0.00275
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-362

Связанные уязвимости

CVSS3: 4.3
ubuntu
около 4 лет назад

By misusing a race in our notification code, an attacker could have forcefully hidden the notification for pages that had received full screen and pointer lock access, which could have been used for spoofing attacks. This vulnerability affects Thunderbird < 91.4.0, Firefox ESR < 91.4.0, and Firefox < 95.

CVSS3: 7.5
redhat
около 4 лет назад

By misusing a race in our notification code, an attacker could have forcefully hidden the notification for pages that had received full screen and pointer lock access, which could have been used for spoofing attacks. This vulnerability affects Thunderbird < 91.4.0, Firefox ESR < 91.4.0, and Firefox < 95.

CVSS3: 4.3
nvd
около 4 лет назад

By misusing a race in our notification code, an attacker could have forcefully hidden the notification for pages that had received full screen and pointer lock access, which could have been used for spoofing attacks. This vulnerability affects Thunderbird < 91.4.0, Firefox ESR < 91.4.0, and Firefox < 95.

CVSS3: 4.3
debian
около 4 лет назад

By misusing a race in our notification code, an attacker could have fo ...

CVSS3: 5.4
fstec
около 4 лет назад

Уязвимость браузера Mozilla Firefox и почтового клиента Mozilla Thunderbird, связанная с ошибками криптографических преобразований, позволяющая нарушителю проводить спуфинг-атаки

EPSS

Процентиль: 51%
0.00275
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-362