Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-g22c-72wp-3974

Опубликовано: 14 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 5.5

Описание

A non-existent chrome.manifest file will attempt to be loaded during startup from the primary installation directory. If a malicious user with local access puts chrome.manifest and other referenced files in this directory, they will be loaded and activated during startup. This could result in malicious software being added without consent or modification of referenced installed files. This vulnerability affects Firefox < 52.

A non-existent chrome.manifest file will attempt to be loaded during startup from the primary installation directory. If a malicious user with local access puts chrome.manifest and other referenced files in this directory, they will be loaded and activated during startup. This could result in malicious software being added without consent or modification of referenced installed files. This vulnerability affects Firefox < 52.

EPSS

Процентиль: 27%
0.00098
Низкий

5.5 Medium

CVSS3

Дефекты

CWE-362

Связанные уязвимости

CVSS3: 5.5
ubuntu
больше 7 лет назад

A non-existent chrome.manifest file will attempt to be loaded during startup from the primary installation directory. If a malicious user with local access puts chrome.manifest and other referenced files in this directory, they will be loaded and activated during startup. This could result in malicious software being added without consent or modification of referenced installed files. This vulnerability affects Firefox < 52.

CVSS3: 5.5
nvd
больше 7 лет назад

A non-existent chrome.manifest file will attempt to be loaded during startup from the primary installation directory. If a malicious user with local access puts chrome.manifest and other referenced files in this directory, they will be loaded and activated during startup. This could result in malicious software being added without consent or modification of referenced installed files. This vulnerability affects Firefox < 52.

CVSS3: 5.5
debian
больше 7 лет назад

A non-existent chrome.manifest file will attempt to be loaded during s ...

suse-cvrf
почти 9 лет назад

Security update for MozillaFirefox, mozilla-nss

EPSS

Процентиль: 27%
0.00098
Низкий

5.5 Medium

CVSS3

Дефекты

CWE-362