Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-jh4r-88h5-574v

Опубликовано: 05 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 6.5

Описание

The unity-firefox-extension package could be tricked into destroying the Unity webapps context, causing Firefox to crash. This could be achieved by spinning the event loop inside the webapps initialization callback. Fixed in 3.0.0+14.04.20140416-0ubuntu1.14.04.1 by shipping an empty package, thus disabling the extension entirely.

The unity-firefox-extension package could be tricked into destroying the Unity webapps context, causing Firefox to crash. This could be achieved by spinning the event loop inside the webapps initialization callback. Fixed in 3.0.0+14.04.20140416-0ubuntu1.14.04.1 by shipping an empty package, thus disabling the extension entirely.

EPSS

Процентиль: 69%
0.01341
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-404

Связанные уязвимости

CVSS3: 4.3
ubuntu
больше 5 лет назад

The unity-firefox-extension package could be tricked into destroying the Unity webapps context, causing Firefox to crash. This could be achieved by spinning the event loop inside the webapps initialization callback. Fixed in 3.0.0+14.04.20140416-0ubuntu1.14.04.1 by shipping an empty package, thus disabling the extension entirely.

CVSS3: 4.3
nvd
больше 5 лет назад

The unity-firefox-extension package could be tricked into destroying the Unity webapps context, causing Firefox to crash. This could be achieved by spinning the event loop inside the webapps initialization callback. Fixed in 3.0.0+14.04.20140416-0ubuntu1.14.04.1 by shipping an empty package, thus disabling the extension entirely.

CVSS3: 4.3
fstec
больше 5 лет назад

Уязвимость пакета Unity-firefox-extension операционной системы Ubuntu, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 69%
0.01341
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-404