Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-j5jj-f68h-7qh9

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 4.3

Описание

Mozilla Firefox before 48.0 does not properly set the LINKABLE and URI_SAFE_FOR_UNTRUSTED_CONTENT flags of about: URLs that are used for error pages, which makes it easier for remote attackers to conduct spoofing attacks via a crafted URL, as demonstrated by misleading text after an about:neterror?d= substring.

Mozilla Firefox before 48.0 does not properly set the LINKABLE and URI_SAFE_FOR_UNTRUSTED_CONTENT flags of about: URLs that are used for error pages, which makes it easier for remote attackers to conduct spoofing attacks via a crafted URL, as demonstrated by misleading text after an about:neterror?d= substring.

EPSS

Процентиль: 63%
0.00443
Низкий

4.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.3
ubuntu
больше 9 лет назад

Mozilla Firefox before 48.0 does not properly set the LINKABLE and URI_SAFE_FOR_UNTRUSTED_CONTENT flags of about: URLs that are used for error pages, which makes it easier for remote attackers to conduct spoofing attacks via a crafted URL, as demonstrated by misleading text after an about:neterror?d= substring.

CVSS3: 4.3
redhat
больше 9 лет назад

Mozilla Firefox before 48.0 does not properly set the LINKABLE and URI_SAFE_FOR_UNTRUSTED_CONTENT flags of about: URLs that are used for error pages, which makes it easier for remote attackers to conduct spoofing attacks via a crafted URL, as demonstrated by misleading text after an about:neterror?d= substring.

CVSS3: 4.3
nvd
больше 9 лет назад

Mozilla Firefox before 48.0 does not properly set the LINKABLE and URI_SAFE_FOR_UNTRUSTED_CONTENT flags of about: URLs that are used for error pages, which makes it easier for remote attackers to conduct spoofing attacks via a crafted URL, as demonstrated by misleading text after an about:neterror?d= substring.

CVSS3: 4.3
debian
больше 9 лет назад

Mozilla Firefox before 48.0 does not properly set the LINKABLE and URI ...

fstec
больше 9 лет назад

Уязвимость браузера Firefox, позволяющая нарушителю проводить спуфинг-атаки

EPSS

Процентиль: 63%
0.00443
Низкий

4.3 Medium

CVSS3