Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-gpjh-cmj6-fjw9

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Mozilla Firefox before 41.0 does not properly restrict the availability of High Resolution Time API times, which allows remote attackers to track last-level cache access, and consequently obtain sensitive information, via crafted JavaScript code that makes performance.now calls.

Mozilla Firefox before 41.0 does not properly restrict the availability of High Resolution Time API times, which allows remote attackers to track last-level cache access, and consequently obtain sensitive information, via crafted JavaScript code that makes performance.now calls.

EPSS

Процентиль: 60%
0.00403
Низкий

Дефекты

CWE-200

Связанные уязвимости

ubuntu
больше 10 лет назад

Mozilla Firefox before 41.0 does not properly restrict the availability of High Resolution Time API times, which allows remote attackers to track last-level cache access, and consequently obtain sensitive information, via crafted JavaScript code that makes performance.now calls.

redhat
больше 10 лет назад

Mozilla Firefox before 41.0 does not properly restrict the availability of High Resolution Time API times, which allows remote attackers to track last-level cache access, and consequently obtain sensitive information, via crafted JavaScript code that makes performance.now calls.

nvd
больше 10 лет назад

Mozilla Firefox before 41.0 does not properly restrict the availability of High Resolution Time API times, which allows remote attackers to track last-level cache access, and consequently obtain sensitive information, via crafted JavaScript code that makes performance.now calls.

debian
больше 10 лет назад

Mozilla Firefox before 41.0 does not properly restrict the availabilit ...

fstec
больше 10 лет назад

Уязвимость браузера Firefox, позволяющая нарушителю получить доступ к защищаемой информации

EPSS

Процентиль: 60%
0.00403
Низкий

Дефекты

CWE-200