Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2019-9798

Опубликовано: 26 апр. 2019
Источник: nvd
CVSS3: 7.4
CVSS2: 5.8
EPSS Низкий

Описание

On Android systems, Firefox can load a library from APITRACE_LIB, which is writable by all users and applications. This could allow malicious third party applications to execute a man-in-the-middle attack if a malicious code was written to that location and loaded. Note: This issue only affects Android. Other operating systems are unaffected.. This vulnerability affects Firefox < 66.

Уязвимые конфигурации

Конфигурация 1

Одновременно

cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*
Версия до 66.0 (исключая)
cpe:2.3:o:google:android:-:*:*:*:*:*:*:*

EPSS

Процентиль: 41%
0.00194
Низкий

7.4 High

CVSS3

5.8 Medium

CVSS2

Дефекты

CWE-426

Связанные уязвимости

CVSS3: 7.4
ubuntu
почти 7 лет назад

On Android systems, Firefox can load a library from APITRACE_LIB, which is writable by all users and applications. This could allow malicious third party applications to execute a man-in-the-middle attack if a malicious code was written to that location and loaded. *Note: This issue only affects Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 66.

CVSS3: 7.4
debian
почти 7 лет назад

On Android systems, Firefox can load a library from APITRACE_LIB, whic ...

github
больше 3 лет назад

On Android systems, Firefox can load a library from APITRACE_LIB, which is writable by all users and applications. This could allow malicious third party applications to execute a man-in-the-middle attack if a malicious code was written to that location and loaded. *Note: This issue only affects Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 66.

CVSS3: 9.8
fstec
почти 7 лет назад

Уязвимость программного обеспечения Firefox, Firefox ESR и Thunderbird, связанная с копированием буфера без проверки размера входных данных, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 41%
0.00194
Низкий

7.4 High

CVSS3

5.8 Medium

CVSS2

Дефекты

CWE-426