Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-jj5p-vxx9-rvj7

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

When reading from areas partially or fully outside the source resource with WebGL's copyTexSubImage method, the specification requires the returned values be zero. Previously, this memory was uninitialized, leading to potentially sensitive data disclosure. This vulnerability affects Thunderbird < 68.7.0, Firefox ESR < 68.7, and Firefox < 75.

When reading from areas partially or fully outside the source resource with WebGL's copyTexSubImage method, the specification requires the returned values be zero. Previously, this memory was uninitialized, leading to potentially sensitive data disclosure. This vulnerability affects Thunderbird < 68.7.0, Firefox ESR < 68.7, and Firefox < 75.

EPSS

Процентиль: 67%
0.00541
Низкий

Дефекты

CWE-119

Связанные уязвимости

CVSS3: 7.5
ubuntu
почти 6 лет назад

When reading from areas partially or fully outside the source resource with WebGL's <code>copyTexSubImage</code> method, the specification requires the returned values be zero. Previously, this memory was uninitialized, leading to potentially sensitive data disclosure. This vulnerability affects Thunderbird < 68.7.0, Firefox ESR < 68.7, and Firefox < 75.

CVSS3: 7.5
redhat
почти 6 лет назад

When reading from areas partially or fully outside the source resource with WebGL's <code>copyTexSubImage</code> method, the specification requires the returned values be zero. Previously, this memory was uninitialized, leading to potentially sensitive data disclosure. This vulnerability affects Thunderbird < 68.7.0, Firefox ESR < 68.7, and Firefox < 75.

CVSS3: 7.5
nvd
почти 6 лет назад

When reading from areas partially or fully outside the source resource with WebGL's <code>copyTexSubImage</code> method, the specification requires the returned values be zero. Previously, this memory was uninitialized, leading to potentially sensitive data disclosure. This vulnerability affects Thunderbird < 68.7.0, Firefox ESR < 68.7, and Firefox < 75.

CVSS3: 7.5
debian
почти 6 лет назад

When reading from areas partially or fully outside the source resource ...

oracle-oval
больше 5 лет назад

ELSA-2020-1429: firefox security update (IMPORTANT)

EPSS

Процентиль: 67%
0.00541
Низкий

Дефекты

CWE-119