Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-15657

Опубликовано: 28 июл. 2020
Источник: redhat
CVSS3: 7.3
EPSS Низкий

Описание

Firefox could be made to load attacker-supplied DLL files from the installation directory. This required an attacker that is already capable of placing files in the installation directory. Note: This issue only affected Windows operating systems. Other operating systems are unaffected.. This vulnerability affects Firefox ESR < 78.1, Firefox < 79, and Thunderbird < 78.1.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5firefoxNot affected
Red Hat Enterprise Linux 5thunderbirdOut of support scope
Red Hat Enterprise Linux 6firefoxOut of support scope
Red Hat Enterprise Linux 6thunderbirdOut of support scope
Red Hat Enterprise Linux 7firefoxWill not fix
Red Hat Enterprise Linux 7thunderbirdWill not fix
Red Hat Enterprise Linux 8firefoxWill not fix
Red Hat Enterprise Linux 8thunderbirdWill not fix

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-426
https://bugzilla.redhat.com/show_bug.cgi?id=1861648Mozilla: DLL hijacking due to incorrect loading path

EPSS

Процентиль: 28%
0.00353
Низкий

7.3 High

CVSS3

Связанные уязвимости

CVSS3: 7.8
ubuntu
около 6 лет назад

Firefox could be made to load attacker-supplied DLL files from the installation directory. This required an attacker that is already capable of placing files in the installation directory. *Note: This issue only affected Windows operating systems. Other operating systems are unaffected.*. This vulnerability affects Firefox ESR < 78.1, Firefox < 79, and Thunderbird < 78.1.

CVSS3: 7.8
nvd
около 6 лет назад

Firefox could be made to load attacker-supplied DLL files from the installation directory. This required an attacker that is already capable of placing files in the installation directory. *Note: This issue only affected Windows operating systems. Other operating systems are unaffected.*. This vulnerability affects Firefox ESR < 78.1, Firefox < 79, and Thunderbird < 78.1.

CVSS3: 7.8
debian
около 6 лет назад

Firefox could be made to load attacker-supplied DLL files from the ins ...

github
больше 4 лет назад

Firefox could be made to load attacker-supplied DLL files from the installation directory. This required an attacker that is already capable of placing files in the installation directory. *Note: This issue only affected Windows operating systems. Other operating systems are unaffected.*. This vulnerability affects Firefox ESR < 78.1, Firefox < 79, and Thunderbird < 78.1.

suse-cvrf
около 6 лет назад

Security update for MozillaFirefox

EPSS

Процентиль: 28%
0.00353
Низкий

7.3 High

CVSS3