Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-jhhg-4257-5g55

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The line-breaking implementation in Mozilla Firefox before 3.5.16 and 3.6.x before 3.6.13, Thunderbird before 3.0.11 and 3.1.x before 3.1.7, and SeaMonkey before 2.0.11 on Windows does not properly handle long strings, which allows remote attackers to execute arbitrary code via a crafted document.write call that triggers a buffer over-read.

The line-breaking implementation in Mozilla Firefox before 3.5.16 and 3.6.x before 3.6.13, Thunderbird before 3.0.11 and 3.1.x before 3.1.7, and SeaMonkey before 2.0.11 on Windows does not properly handle long strings, which allows remote attackers to execute arbitrary code via a crafted document.write call that triggers a buffer over-read.

EPSS

Процентиль: 91%
0.06622
Низкий

Дефекты

CWE-119

Связанные уязвимости

ubuntu
около 15 лет назад

The line-breaking implementation in Mozilla Firefox before 3.5.16 and 3.6.x before 3.6.13, Thunderbird before 3.0.11 and 3.1.x before 3.1.7, and SeaMonkey before 2.0.11 on Windows does not properly handle long strings, which allows remote attackers to execute arbitrary code via a crafted document.write call that triggers a buffer over-read.

nvd
около 15 лет назад

The line-breaking implementation in Mozilla Firefox before 3.5.16 and 3.6.x before 3.6.13, Thunderbird before 3.0.11 and 3.1.x before 3.1.7, and SeaMonkey before 2.0.11 on Windows does not properly handle long strings, which allows remote attackers to execute arbitrary code via a crafted document.write call that triggers a buffer over-read.

debian
около 15 лет назад

The line-breaking implementation in Mozilla Firefox before 3.5.16 and ...

EPSS

Процентиль: 91%
0.06622
Низкий

Дефекты

CWE-119