Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2009-5017

Опубликовано: 21 авг. 2009
Источник: redhat
CVSS2: 4.3
EPSS Низкий

Описание

Mozilla Firefox before 3.6 Beta 3 does not properly handle overlong UTF-8 encoding, which makes it easier for remote attackers to bypass cross-site scripting (XSS) protection mechanisms via a crafted string, a different vulnerability than CVE-2010-1210.

Дополнительная информация

Статус:

Low
https://bugzilla.redhat.com/show_bug.cgi?id=656287Firefox: overlong UTF-8 seqence detection problem

EPSS

Процентиль: 38%
0.00166
Низкий

4.3 Medium

CVSS2

Связанные уязвимости

ubuntu
почти 15 лет назад

Mozilla Firefox before 3.6 Beta 3 does not properly handle overlong UTF-8 encoding, which makes it easier for remote attackers to bypass cross-site scripting (XSS) protection mechanisms via a crafted string, a different vulnerability than CVE-2010-1210.

nvd
почти 15 лет назад

Mozilla Firefox before 3.6 Beta 3 does not properly handle overlong UTF-8 encoding, which makes it easier for remote attackers to bypass cross-site scripting (XSS) protection mechanisms via a crafted string, a different vulnerability than CVE-2010-1210.

debian
почти 15 лет назад

Mozilla Firefox before 3.6 Beta 3 does not properly handle overlong UT ...

github
больше 3 лет назад

Mozilla Firefox before 3.6 Beta 3 does not properly handle overlong UTF-8 encoding, which makes it easier for remote attackers to bypass cross-site scripting (XSS) protection mechanisms via a crafted string, a different vulnerability than CVE-2010-1210.

oracle-oval
около 15 лет назад

ELSA-2010-0501: firefox security, bug fix, and enhancement update (CRITICAL)

EPSS

Процентиль: 38%
0.00166
Низкий

4.3 Medium

CVSS2