Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-f56r-gj93-xc2f

Опубликовано: 13 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 8.8

Описание

The nsDisplayList::HitTest function in Mozilla Firefox before 48.0 and Firefox ESR 45.x before 45.3 mishandles rendering display transformation, which allows remote attackers to execute arbitrary code via a crafted web site that leverages "type confusion."

The nsDisplayList::HitTest function in Mozilla Firefox before 48.0 and Firefox ESR 45.x before 45.3 mishandles rendering display transformation, which allows remote attackers to execute arbitrary code via a crafted web site that leverages "type confusion."

EPSS

Процентиль: 72%
0.00752
Низкий

8.8 High

CVSS3

Дефекты

CWE-704

Связанные уязвимости

CVSS3: 8.8
ubuntu
около 9 лет назад

The nsDisplayList::HitTest function in Mozilla Firefox before 48.0 and Firefox ESR 45.x before 45.3 mishandles rendering display transformation, which allows remote attackers to execute arbitrary code via a crafted web site that leverages "type confusion."

CVSS3: 8.8
redhat
около 9 лет назад

The nsDisplayList::HitTest function in Mozilla Firefox before 48.0 and Firefox ESR 45.x before 45.3 mishandles rendering display transformation, which allows remote attackers to execute arbitrary code via a crafted web site that leverages "type confusion."

CVSS3: 8.8
nvd
около 9 лет назад

The nsDisplayList::HitTest function in Mozilla Firefox before 48.0 and Firefox ESR 45.x before 45.3 mishandles rendering display transformation, which allows remote attackers to execute arbitrary code via a crafted web site that leverages "type confusion."

CVSS3: 8.8
debian
около 9 лет назад

The nsDisplayList::HitTest function in Mozilla Firefox before 48.0 and ...

fstec
около 9 лет назад

Уязвимость браузеров Firefox и Firefox ESR, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 72%
0.00752
Низкий

8.8 High

CVSS3

Дефекты

CWE-704