Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-cr94-c6j4-q6g5

Опубликовано: 06 авг. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 8.1

Описание

The date picker could partially obscure security prompts. This could be used by a malicious site to trick a user into granting permissions. This vulnerability affects Firefox < 129, Firefox ESR < 115.14, and Firefox ESR < 128.1.

The date picker could partially obscure security prompts. This could be used by a malicious site to trick a user into granting permissions. This vulnerability affects Firefox < 129, Firefox ESR < 115.14, and Firefox ESR < 128.1.

EPSS

Процентиль: 40%
0.00177
Низкий

8.1 High

CVSS3

Дефекты

CWE-451

Связанные уязвимости

CVSS3: 6.5
ubuntu
11 месяцев назад

The date picker could partially obscure security prompts. This could be used by a malicious site to trick a user into granting permissions. This vulnerability affects Firefox < 129, Firefox ESR < 115.14, Firefox ESR < 128.1, Thunderbird < 128.1, and Thunderbird < 115.14.

CVSS3: 6.1
redhat
11 месяцев назад

The date picker could partially obscure security prompts. This could be used by a malicious site to trick a user into granting permissions. This vulnerability affects Firefox < 129, Firefox ESR < 115.14, Firefox ESR < 128.1, Thunderbird < 128.1, and Thunderbird < 115.14.

CVSS3: 6.5
nvd
11 месяцев назад

The date picker could partially obscure security prompts. This could be used by a malicious site to trick a user into granting permissions. This vulnerability affects Firefox < 129, Firefox ESR < 115.14, Firefox ESR < 128.1, Thunderbird < 128.1, and Thunderbird < 115.14.

CVSS3: 6.5
debian
11 месяцев назад

The date picker could partially obscure security prompts. This could b ...

CVSS3: 8.1
fstec
11 месяцев назад

Уязвимость функции Date Picker («Выбор даты») браузеров Mozilla Firefox, Firefox ESR, позволяющая нарушителю предоставить произвольные разрешения и получить несанкционированный доступ к данным или функциям

EPSS

Процентиль: 40%
0.00177
Низкий

8.1 High

CVSS3

Дефекты

CWE-451