Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-w696-j5x3-hhvj

Опубликовано: 22 дек. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 8.6

Описание

An attacker who compromised a content process could have partially escaped the sandbox to read arbitrary files via clipboard-related IPC messages.
This bug only affects Thunderbird for Linux. Other operating systems are unaffected.. This vulnerability affects Firefox < 108, Firefox ESR < 102.6, and Thunderbird < 102.6.

An attacker who compromised a content process could have partially escaped the sandbox to read arbitrary files via clipboard-related IPC messages.
This bug only affects Thunderbird for Linux. Other operating systems are unaffected.. This vulnerability affects Firefox < 108, Firefox ESR < 102.6, and Thunderbird < 102.6.

EPSS

Процентиль: 42%
0.002
Низкий

8.6 High

CVSS3

Дефекты

CWE-125

Связанные уязвимости

CVSS3: 8.6
ubuntu
почти 3 года назад

An attacker who compromised a content process could have partially escaped the sandbox to read arbitrary files via clipboard-related IPC messages.<br>*This bug only affects Thunderbird for Linux. Other operating systems are unaffected.*. This vulnerability affects Firefox < 108, Firefox ESR < 102.6, and Thunderbird < 102.6.

CVSS3: 8.6
redhat
почти 3 года назад

An attacker who compromised a content process could have partially escaped the sandbox to read arbitrary files via clipboard-related IPC messages.<br>*This bug only affects Thunderbird for Linux. Other operating systems are unaffected.*. This vulnerability affects Firefox < 108, Firefox ESR < 102.6, and Thunderbird < 102.6.

CVSS3: 8.6
nvd
почти 3 года назад

An attacker who compromised a content process could have partially escaped the sandbox to read arbitrary files via clipboard-related IPC messages.<br>*This bug only affects Thunderbird for Linux. Other operating systems are unaffected.*. This vulnerability affects Firefox < 108, Firefox ESR < 102.6, and Thunderbird < 102.6.

CVSS3: 8.6
debian
почти 3 года назад

An attacker who compromised a content process could have partially esc ...

CVSS3: 7.5
redos
почти 3 года назад

Уязвимость Thunderbird

EPSS

Процентиль: 42%
0.002
Низкий

8.6 High

CVSS3

Дефекты

CWE-125