Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-12388

Опубликовано: 05 мая 2020
Источник: redhat
CVSS3: 10
EPSS Низкий

Описание

The Firefox content processes did not sufficiently lockdown access control which could result in a sandbox escape. Note: this issue only affects Firefox on Windows operating systems.. This vulnerability affects Firefox ESR < 68.8 and Firefox < 76.

The Mozilla Foundation Security Advisory describes this flaw as: The Firefox content processes did not sufficiently lockdown access control which could result in a sandbox escape.

Отчет

This issue only affects Firefox on Windows operating systems. Firefox on Linux is not affected.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5firefoxOut of support scope
Red Hat Enterprise Linux 6firefoxNot affected
Red Hat Enterprise Linux 7firefoxNot affected
Red Hat Enterprise Linux 8firefoxNot affected

Показывать по

Дополнительная информация

Статус:

Critical
Дефект:
CWE-284
https://bugzilla.redhat.com/show_bug.cgi?id=1831944Mozilla: Sandbox escape with improperly guarded Access Tokens

EPSS

Процентиль: 81%
0.01503
Низкий

10 Critical

CVSS3

Связанные уязвимости

CVSS3: 10
ubuntu
больше 5 лет назад

The Firefox content processes did not sufficiently lockdown access control which could result in a sandbox escape. *Note: this issue only affects Firefox on Windows operating systems.*. This vulnerability affects Firefox ESR < 68.8 and Firefox < 76.

CVSS3: 10
nvd
больше 5 лет назад

The Firefox content processes did not sufficiently lockdown access control which could result in a sandbox escape. *Note: this issue only affects Firefox on Windows operating systems.*. This vulnerability affects Firefox ESR < 68.8 and Firefox < 76.

CVSS3: 10
debian
больше 5 лет назад

The Firefox content processes did not sufficiently lockdown access con ...

CVSS3: 10
github
больше 3 лет назад

The Firefox content processes did not sufficiently lockdown access control which could result in a sandbox escape. *Note: this issue only affects Firefox on Windows operating systems.*. This vulnerability affects Firefox ESR < 68.8 and Firefox < 76.

CVSS3: 10
fstec
почти 6 лет назад

Уязвимость веб-браузеров Firefox ESR и Firefox, связанная с недостаточной проверкой входных данных, позволяющая нарушителю выполнить произаольный код

EPSS

Процентиль: 81%
0.01503
Низкий

10 Critical

CVSS3