Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-vxw8-wvxp-5f2r

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Firefox could be made to load attacker-supplied DLL files from the installation directory. This required an attacker that is already capable of placing files in the installation directory. Note: This issue only affected Windows operating systems. Other operating systems are unaffected.. This vulnerability affects Firefox ESR < 78.1, Firefox < 79, and Thunderbird < 78.1.

Firefox could be made to load attacker-supplied DLL files from the installation directory. This required an attacker that is already capable of placing files in the installation directory. Note: This issue only affected Windows operating systems. Other operating systems are unaffected.. This vulnerability affects Firefox ESR < 78.1, Firefox < 79, and Thunderbird < 78.1.

EPSS

Процентиль: 42%
0.00199
Низкий

Связанные уязвимости

CVSS3: 7.8
ubuntu
больше 5 лет назад

Firefox could be made to load attacker-supplied DLL files from the installation directory. This required an attacker that is already capable of placing files in the installation directory. *Note: This issue only affected Windows operating systems. Other operating systems are unaffected.*. This vulnerability affects Firefox ESR < 78.1, Firefox < 79, and Thunderbird < 78.1.

CVSS3: 7.3
redhat
больше 5 лет назад

Firefox could be made to load attacker-supplied DLL files from the installation directory. This required an attacker that is already capable of placing files in the installation directory. *Note: This issue only affected Windows operating systems. Other operating systems are unaffected.*. This vulnerability affects Firefox ESR < 78.1, Firefox < 79, and Thunderbird < 78.1.

CVSS3: 7.8
nvd
больше 5 лет назад

Firefox could be made to load attacker-supplied DLL files from the installation directory. This required an attacker that is already capable of placing files in the installation directory. *Note: This issue only affected Windows operating systems. Other operating systems are unaffected.*. This vulnerability affects Firefox ESR < 78.1, Firefox < 79, and Thunderbird < 78.1.

CVSS3: 7.8
debian
больше 5 лет назад

Firefox could be made to load attacker-supplied DLL files from the ins ...

suse-cvrf
больше 5 лет назад

Security update for MozillaFirefox

EPSS

Процентиль: 42%
0.00199
Низкий