Описание
Sandbox escape due to integer overflow in the Graphics component. This vulnerability was fixed in Firefox 147, Firefox ESR 115.32, Firefox ESR 140.7, Thunderbird 147, and Thunderbird 140.7.
Ссылки
- Permissions Required
- Vendor Advisory
- Vendor Advisory
- Vendor Advisory
- Vendor Advisory
- Vendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 115.32.0 (исключая)Версия до 147.0 (исключая)Версия от 128.0 (включая) до 140.7.0 (исключая)Версия до 140.7.0 (исключая)Версия до 147.0 (исключая)
Одно из
cpe:2.3:a:mozilla:firefox:*:*:*:*:esr:*:*:*
cpe:2.3:a:mozilla:firefox:*:*:*:*:-:*:*:*
cpe:2.3:a:mozilla:firefox:*:*:*:*:esr:*:*:*
cpe:2.3:a:mozilla:thunderbird:*:*:*:*:esr:*:*:*
cpe:2.3:a:mozilla:thunderbird:*:*:*:*:-:*:*:*
EPSS
Процентиль: 50%
0.00664
Низкий
8.8 High
CVSS3
7.5 High
CVSS3
Дефекты
CWE-190
Связанные уязвимости
CVSS3: 8.8
ubuntu
8 месяцев назад
Sandbox escape due to integer overflow in the Graphics component. This vulnerability was fixed in Firefox 147, Firefox ESR 115.32, Firefox ESR 140.7, Thunderbird 147, and Thunderbird 140.7.
CVSS3: 7.5
redhat
8 месяцев назад
Sandbox escape due to integer overflow in the Graphics component. This vulnerability was fixed in Firefox 147, Firefox ESR 115.32, Firefox ESR 140.7, Thunderbird 147, and Thunderbird 140.7.
CVSS3: 8.8
debian
8 месяцев назад
Sandbox escape due to integer overflow in the Graphics component. This ...
EPSS
Процентиль: 50%
0.00664
Низкий
8.8 High
CVSS3
7.5 High
CVSS3
Дефекты
CWE-190