Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-x4cw-r9m3-pj4c

Опубликовано: 14 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 8.6

Описание

A lack of parameter validation on IPC messages results in a potential out-of-bounds write through malformed IPC messages. This can potentially allow for sandbox escape through memory corruption in the parent process. This vulnerability affects Thunderbird < 52.7, Firefox ESR < 52.7, and Firefox < 59.

A lack of parameter validation on IPC messages results in a potential out-of-bounds write through malformed IPC messages. This can potentially allow for sandbox escape through memory corruption in the parent process. This vulnerability affects Thunderbird < 52.7, Firefox ESR < 52.7, and Firefox < 59.

EPSS

Процентиль: 84%
0.02394
Низкий

8.6 High

CVSS3

Дефекты

CWE-787

Связанные уязвимости

CVSS3: 8.6
ubuntu
около 7 лет назад

A lack of parameter validation on IPC messages results in a potential out-of-bounds write through malformed IPC messages. This can potentially allow for sandbox escape through memory corruption in the parent process. This vulnerability affects Thunderbird < 52.7, Firefox ESR < 52.7, and Firefox < 59.

CVSS3: 8.6
redhat
больше 7 лет назад

A lack of parameter validation on IPC messages results in a potential out-of-bounds write through malformed IPC messages. This can potentially allow for sandbox escape through memory corruption in the parent process. This vulnerability affects Thunderbird < 52.7, Firefox ESR < 52.7, and Firefox < 59.

CVSS3: 8.6
nvd
около 7 лет назад

A lack of parameter validation on IPC messages results in a potential out-of-bounds write through malformed IPC messages. This can potentially allow for sandbox escape through memory corruption in the parent process. This vulnerability affects Thunderbird < 52.7, Firefox ESR < 52.7, and Firefox < 59.

CVSS3: 8.6
debian
около 7 лет назад

A lack of parameter validation on IPC messages results in a potential ...

CVSS3: 8.6
fstec
больше 7 лет назад

Уязвимость браузеров Mozilla Firefox, Firefox ESR и почтового клиента Thunderbird, связанная с отсутствием проверки параметров в IPC-сообщениях, позволяющая нарушителю оказать воздействие на целостность данных

EPSS

Процентиль: 84%
0.02394
Низкий

8.6 High

CVSS3

Дефекты

CWE-787