Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-r3rp-58g5-pvr5

Опубликовано: 13 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 8.8

Описание

When the RSS Feed preview about:feeds page is framed within another page, it can be used in concert with scripted content for a clickjacking attack that confuses users into downloading and executing an executable file from a temporary directory. Note: This issue only affects Windows operating systems. Other operating systems are not affected.. This vulnerability affects Firefox < 64.

When the RSS Feed preview about:feeds page is framed within another page, it can be used in concert with scripted content for a clickjacking attack that confuses users into downloading and executing an executable file from a temporary directory. Note: This issue only affects Windows operating systems. Other operating systems are not affected.. This vulnerability affects Firefox < 64.

EPSS

Процентиль: 61%
0.00417
Низкий

8.8 High

CVSS3

Дефекты

CWE-1021

Связанные уязвимости

CVSS3: 8.8
ubuntu
почти 7 лет назад

When the RSS Feed preview about:feeds page is framed within another page, it can be used in concert with scripted content for a clickjacking attack that confuses users into downloading and executing an executable file from a temporary directory. *Note: This issue only affects Windows operating systems. Other operating systems are not affected.*. This vulnerability affects Firefox < 64.

CVSS3: 8.8
nvd
почти 7 лет назад

When the RSS Feed preview about:feeds page is framed within another page, it can be used in concert with scripted content for a clickjacking attack that confuses users into downloading and executing an executable file from a temporary directory. *Note: This issue only affects Windows operating systems. Other operating systems are not affected.*. This vulnerability affects Firefox < 64.

CVSS3: 8.8
debian
почти 7 лет назад

When the RSS Feed preview about:feeds page is framed within another pa ...

CVSS3: 8.8
fstec
почти 7 лет назад

Уязвимость браузера Firefox, связанная с недостаточной проверкой вводимых данных, позволяющая нарушителю получить доступ к конфиденциальным данным, нарушить их целостность, а также вызвать отказ в обслуживании

EPSS

Процентиль: 61%
0.00417
Низкий

8.8 High

CVSS3

Дефекты

CWE-1021