Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-g67q-47ww-68wp

Опубликовано: 02 июн. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 8.8

Описание

After downloading a Windows .scf script from the local filesystem, an attacker could supply a remote path that would lead to unexpected network requests from the operating system. This also had the potential to leak NTLM credentials to the resource.
This bug only affects Firefox for Windows. Other operating systems are unaffected.. This vulnerability affects Firefox < 110.

After downloading a Windows .scf script from the local filesystem, an attacker could supply a remote path that would lead to unexpected network requests from the operating system. This also had the potential to leak NTLM credentials to the resource.
This bug only affects Firefox for Windows. Other operating systems are unaffected.. This vulnerability affects Firefox < 110.

EPSS

Процентиль: 46%
0.00231
Низкий

8.8 High

CVSS3

Дефекты

CWE-522

Связанные уязвимости

CVSS3: 8.8
ubuntu
больше 2 лет назад

After downloading a Windows <code>.scf</code> script from the local filesystem, an attacker could supply a remote path that would lead to unexpected network requests from the operating system. This also had the potential to leak NTLM credentials to the resource.<br>*This bug only affects Firefox for Windows. Other operating systems are unaffected.*. This vulnerability affects Firefox < 110.

CVSS3: 6.1
redhat
почти 3 года назад

After downloading a Windows <code>.scf</code> script from the local filesystem, an attacker could supply a remote path that would lead to unexpected network requests from the operating system. This also had the potential to leak NTLM credentials to the resource.<br>*This bug only affects Firefox for Windows. Other operating systems are unaffected.*. This vulnerability affects Firefox < 110.

CVSS3: 8.8
nvd
больше 2 лет назад

After downloading a Windows <code>.scf</code> script from the local filesystem, an attacker could supply a remote path that would lead to unexpected network requests from the operating system. This also had the potential to leak NTLM credentials to the resource.<br>*This bug only affects Firefox for Windows. Other operating systems are unaffected.*. This vulnerability affects Firefox < 110.

CVSS3: 8.8
debian
больше 2 лет назад

After downloading a Windows <code>.scf</code> script from the local fi ...

CVSS3: 8.8
fstec
больше 2 лет назад

Уязвимость браузера Mozilla Firefox операционных систем Windows, связанная с ошибками в настройках безопасности, позволяющая нарушителю получить доступ к конфиденциальной информации

EPSS

Процентиль: 46%
0.00231
Низкий

8.8 High

CVSS3

Дефекты

CWE-522