Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2022-38474

Опубликовано: 22 дек. 2022
Источник: nvd
CVSS3: 4.3
EPSS Низкий

Описание

A website that had permission to access the microphone could record audio without the audio notification being shown. This bug does not allow the attacker to bypass the permission prompt - it only affects the notification shown once permission has been granted.
This bug only affects Firefox for Android. Other operating systems are unaffected.. This vulnerability affects Firefox < 104.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:mozilla:firefox:*:*:*:*:*:android:*:*
Версия до 104.0 (исключая)

EPSS

Процентиль: 41%
0.00191
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-668
CWE-668

Связанные уязвимости

CVSS3: 4.3
ubuntu
около 3 лет назад

A website that had permission to access the microphone could record audio without the audio notification being shown. This bug does not allow the attacker to bypass the permission prompt - it only affects the notification shown once permission has been granted.<br />*This bug only affects Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 104.

CVSS3: 4.3
debian
около 3 лет назад

A website that had permission to access the microphone could record au ...

CVSS3: 4.3
github
около 3 лет назад

A website that had permission to access the microphone could record audio without the audio notification being shown. This bug does not allow the attacker to bypass the permission prompt - it only affects the notification shown once permission has been granted.<br />*This bug only affects Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 104.

EPSS

Процентиль: 41%
0.00191
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-668
CWE-668