Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-cv8q-mpvf-42h2

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 8.1

Описание

Under certain conditions, when running the nsDocShell destructor, a race condition can cause a use-after-free. We are aware of targeted attacks in the wild abusing this flaw. This vulnerability affects Thunderbird < 68.7.0, Firefox < 74.0.1, and Firefox ESR < 68.6.1.

Under certain conditions, when running the nsDocShell destructor, a race condition can cause a use-after-free. We are aware of targeted attacks in the wild abusing this flaw. This vulnerability affects Thunderbird < 68.7.0, Firefox < 74.0.1, and Firefox ESR < 68.6.1.

EPSS

Процентиль: 55%
0.00329
Низкий

8.1 High

CVSS3

Дефекты

CWE-362
CWE-416
CWE-787

Связанные уязвимости

CVSS3: 8.1
ubuntu
почти 6 лет назад

Under certain conditions, when running the nsDocShell destructor, a race condition can cause a use-after-free. We are aware of targeted attacks in the wild abusing this flaw. This vulnerability affects Thunderbird < 68.7.0, Firefox < 74.0.1, and Firefox ESR < 68.6.1.

CVSS3: 8.8
redhat
почти 6 лет назад

Under certain conditions, when running the nsDocShell destructor, a race condition can cause a use-after-free. We are aware of targeted attacks in the wild abusing this flaw. This vulnerability affects Thunderbird < 68.7.0, Firefox < 74.0.1, and Firefox ESR < 68.6.1.

CVSS3: 8.1
nvd
почти 6 лет назад

Under certain conditions, when running the nsDocShell destructor, a race condition can cause a use-after-free. We are aware of targeted attacks in the wild abusing this flaw. This vulnerability affects Thunderbird < 68.7.0, Firefox < 74.0.1, and Firefox ESR < 68.6.1.

CVSS3: 8.1
debian
почти 6 лет назад

Under certain conditions, when running the nsDocShell destructor, a ra ...

CVSS3: 6.3
fstec
почти 6 лет назад

Уязвимость деструктора nsDocShell веб-браузеров Firefox ESR и Firefox и почтового клиента Thunderbird, позволяющая нарушителю получить доступ к конфиденциальным данным, нарушить их целостность, а также вызвать отказ в обслуживании

EPSS

Процентиль: 55%
0.00329
Низкий

8.1 High

CVSS3

Дефекты

CWE-362
CWE-416
CWE-787