Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-jh4r-88h5-574v

Опубликовано: 05 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 6.5

Описание

The unity-firefox-extension package could be tricked into destroying the Unity webapps context, causing Firefox to crash. This could be achieved by spinning the event loop inside the webapps initialization callback. Fixed in 3.0.0+14.04.20140416-0ubuntu1.14.04.1 by shipping an empty package, thus disabling the extension entirely.

The unity-firefox-extension package could be tricked into destroying the Unity webapps context, causing Firefox to crash. This could be achieved by spinning the event loop inside the webapps initialization callback. Fixed in 3.0.0+14.04.20140416-0ubuntu1.14.04.1 by shipping an empty package, thus disabling the extension entirely.

EPSS

Процентиль: 37%
0.00162
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-404

Связанные уязвимости

CVSS3: 4.3
ubuntu
почти 5 лет назад

The unity-firefox-extension package could be tricked into destroying the Unity webapps context, causing Firefox to crash. This could be achieved by spinning the event loop inside the webapps initialization callback. Fixed in 3.0.0+14.04.20140416-0ubuntu1.14.04.1 by shipping an empty package, thus disabling the extension entirely.

CVSS3: 4.3
nvd
почти 5 лет назад

The unity-firefox-extension package could be tricked into destroying the Unity webapps context, causing Firefox to crash. This could be achieved by spinning the event loop inside the webapps initialization callback. Fixed in 3.0.0+14.04.20140416-0ubuntu1.14.04.1 by shipping an empty package, thus disabling the extension entirely.

CVSS3: 4.3
fstec
почти 5 лет назад

Уязвимость пакета Unity-firefox-extension операционной системы Ubuntu, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 37%
0.00162
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-404