Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-xqrw-qq76-h9pm

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью

Описание

html/parser/XSSAuditor.cpp in WebCore in WebKit, as used in Google Chrome through 22 and Safari 5.1.7, does not consider all possible output contexts of reflected data, which makes it easier for remote attackers to bypass a cross-site scripting (XSS) protection mechanism via a crafted string, aka rdar problem 12019108.

html/parser/XSSAuditor.cpp in WebCore in WebKit, as used in Google Chrome through 22 and Safari 5.1.7, does not consider all possible output contexts of reflected data, which makes it easier for remote attackers to bypass a cross-site scripting (XSS) protection mechanism via a crafted string, aka rdar problem 12019108.

EPSS

Процентиль: 56%
0.00344
Низкий

Дефекты

CWE-79

Связанные уязвимости

ubuntu
около 13 лет назад

html/parser/XSSAuditor.cpp in WebCore in WebKit, as used in Google Chrome through 22 and Safari 5.1.7, does not consider all possible output contexts of reflected data, which makes it easier for remote attackers to bypass a cross-site scripting (XSS) protection mechanism via a crafted string, aka rdar problem 12019108.

nvd
около 13 лет назад

html/parser/XSSAuditor.cpp in WebCore in WebKit, as used in Google Chrome through 22 and Safari 5.1.7, does not consider all possible output contexts of reflected data, which makes it easier for remote attackers to bypass a cross-site scripting (XSS) protection mechanism via a crafted string, aka rdar problem 12019108.

debian
около 13 лет назад

html/parser/XSSAuditor.cpp in WebCore in WebKit, as used in Google Chr ...

EPSS

Процентиль: 56%
0.00344
Низкий

Дефекты

CWE-79