Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-wxv2-7x8x-wpcq

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The TCP Socket API implementation in Mozilla Firefox before 41.0 mishandles array boundaries that were established with a navigator.mozTCPSocket.open method call and send method calls, which allows remote TCP servers to obtain sensitive information from process memory by reading packet data, as demonstrated by availability of this API in a Firefox OS application.

The TCP Socket API implementation in Mozilla Firefox before 41.0 mishandles array boundaries that were established with a navigator.mozTCPSocket.open method call and send method calls, which allows remote TCP servers to obtain sensitive information from process memory by reading packet data, as demonstrated by availability of this API in a Firefox OS application.

EPSS

Процентиль: 69%
0.00629
Низкий

Дефекты

CWE-200

Связанные уязвимости

ubuntu
почти 10 лет назад

The TCP Socket API implementation in Mozilla Firefox before 41.0 mishandles array boundaries that were established with a navigator.mozTCPSocket.open method call and send method calls, which allows remote TCP servers to obtain sensitive information from process memory by reading packet data, as demonstrated by availability of this API in a Firefox OS application.

redhat
почти 10 лет назад

The TCP Socket API implementation in Mozilla Firefox before 41.0 mishandles array boundaries that were established with a navigator.mozTCPSocket.open method call and send method calls, which allows remote TCP servers to obtain sensitive information from process memory by reading packet data, as demonstrated by availability of this API in a Firefox OS application.

nvd
почти 10 лет назад

The TCP Socket API implementation in Mozilla Firefox before 41.0 mishandles array boundaries that were established with a navigator.mozTCPSocket.open method call and send method calls, which allows remote TCP servers to obtain sensitive information from process memory by reading packet data, as demonstrated by availability of this API in a Firefox OS application.

debian
почти 10 лет назад

The TCP Socket API implementation in Mozilla Firefox before 41.0 misha ...

fstec
почти 10 лет назад

Уязвимость браузера Firefox, позволяющая нарушителю получить доступ к защищаемой информации из памяти процесса

EPSS

Процентиль: 69%
0.00629
Низкий

Дефекты

CWE-200