Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-qc4r-65pv-9r8p

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью

Описание

PDF.js in Mozilla Firefox before 25.0 and Firefox ESR 24.x before 24.1 does not properly handle the appending of an IFRAME element, which allows remote attackers to read arbitrary files or execute arbitrary JavaScript code with chrome privileges by using this element within an embedded PDF object.

PDF.js in Mozilla Firefox before 25.0 and Firefox ESR 24.x before 24.1 does not properly handle the appending of an IFRAME element, which allows remote attackers to read arbitrary files or execute arbitrary JavaScript code with chrome privileges by using this element within an embedded PDF object.

EPSS

Процентиль: 73%
0.00781
Низкий

Связанные уязвимости

ubuntu
больше 12 лет назад

PDF.js in Mozilla Firefox before 25.0 and Firefox ESR 24.x before 24.1 does not properly handle the appending of an IFRAME element, which allows remote attackers to read arbitrary files or execute arbitrary JavaScript code with chrome privileges by using this element within an embedded PDF object.

redhat
больше 12 лет назад

PDF.js in Mozilla Firefox before 25.0 and Firefox ESR 24.x before 24.1 does not properly handle the appending of an IFRAME element, which allows remote attackers to read arbitrary files or execute arbitrary JavaScript code with chrome privileges by using this element within an embedded PDF object.

nvd
больше 12 лет назад

PDF.js in Mozilla Firefox before 25.0 and Firefox ESR 24.x before 24.1 does not properly handle the appending of an IFRAME element, which allows remote attackers to read arbitrary files or execute arbitrary JavaScript code with chrome privileges by using this element within an embedded PDF object.

debian
больше 12 лет назад

PDF.js in Mozilla Firefox before 25.0 and Firefox ESR 24.x before 24.1 ...

EPSS

Процентиль: 73%
0.00781
Низкий