Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-h2cq-jrvg-h8x6

Опубликовано: 13 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Mozilla Firefox before 16.0, Thunderbird before 16.0, and SeaMonkey before 2.13 do not properly implement the HTML5 Same Origin Policy, which allows remote attackers to conduct cross-site scripting (XSS) attacks by leveraging initial-origin access after document.domain has been set.

Mozilla Firefox before 16.0, Thunderbird before 16.0, and SeaMonkey before 2.13 do not properly implement the HTML5 Same Origin Policy, which allows remote attackers to conduct cross-site scripting (XSS) attacks by leveraging initial-origin access after document.domain has been set.

EPSS

Процентиль: 78%
0.01914
Низкий

Дефекты

CWE-79

Связанные уязвимости

ubuntu
почти 14 лет назад

Mozilla Firefox before 16.0, Thunderbird before 16.0, and SeaMonkey before 2.13 do not properly implement the HTML5 Same Origin Policy, which allows remote attackers to conduct cross-site scripting (XSS) attacks by leveraging initial-origin access after document.domain has been set.

redhat
почти 14 лет назад

Mozilla Firefox before 16.0, Thunderbird before 16.0, and SeaMonkey before 2.13 do not properly implement the HTML5 Same Origin Policy, which allows remote attackers to conduct cross-site scripting (XSS) attacks by leveraging initial-origin access after document.domain has been set.

nvd
почти 14 лет назад

Mozilla Firefox before 16.0, Thunderbird before 16.0, and SeaMonkey before 2.13 do not properly implement the HTML5 Same Origin Policy, which allows remote attackers to conduct cross-site scripting (XSS) attacks by leveraging initial-origin access after document.domain has been set.

debian
почти 14 лет назад

Mozilla Firefox before 16.0, Thunderbird before 16.0, and SeaMonkey be ...

EPSS

Процентиль: 78%
0.01914
Низкий

Дефекты

CWE-79