Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2021-23961

Опубликовано: 19 апр. 2021
Источник: redhat
CVSS3: 7.4
EPSS Низкий

Описание

Further techniques that built on the slipstream research combined with a malicious webpage could have exposed both an internal network's hosts as well as services running on the user's local machine. This vulnerability affects Firefox < 85.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6firefoxOut of support scope
Red Hat Enterprise Linux 6thunderbirdOut of support scope
Red Hat Enterprise Linux 7thunderbirdFixedRHSA-2021:135026.04.2021
Red Hat Enterprise Linux 7firefoxFixedRHSA-2021:136326.04.2021
Red Hat Enterprise Linux 8thunderbirdFixedRHSA-2021:135326.04.2021
Red Hat Enterprise Linux 8firefoxFixedRHSA-2021:136026.04.2021
Red Hat Enterprise Linux 8.1 Extended Update SupportthunderbirdFixedRHSA-2021:135126.04.2021
Red Hat Enterprise Linux 8.1 Extended Update SupportfirefoxFixedRHSA-2021:136226.04.2021
Red Hat Enterprise Linux 8.2 Extended Update SupportthunderbirdFixedRHSA-2021:135226.04.2021
Red Hat Enterprise Linux 8.2 Extended Update SupportfirefoxFixedRHSA-2021:136126.04.2021

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-200
https://bugzilla.redhat.com/show_bug.cgi?id=1951367Mozilla: More internal network hosts could have been probed by a malicious webpage

EPSS

Процентиль: 61%
0.00417
Низкий

7.4 High

CVSS3

Связанные уязвимости

CVSS3: 7.4
ubuntu
больше 4 лет назад

Further techniques that built on the slipstream research combined with a malicious webpage could have exposed both an internal network's hosts as well as services running on the user's local machine. This vulnerability affects Firefox < 85.

CVSS3: 7.4
nvd
больше 4 лет назад

Further techniques that built on the slipstream research combined with a malicious webpage could have exposed both an internal network's hosts as well as services running on the user's local machine. This vulnerability affects Firefox < 85.

CVSS3: 7.4
debian
больше 4 лет назад

Further techniques that built on the slipstream research combined with ...

CVSS3: 7.4
github
около 3 лет назад

Further techniques that built on the slipstream research combined with a malicious webpage could have exposed both an internal network's hosts as well as services running on the user's local machine. This vulnerability affects Firefox < 85.

CVSS3: 7.4
fstec
больше 4 лет назад

Уязвимость браузера Mozilla Firefox, связанная с раскрытием информации, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

EPSS

Процентиль: 61%
0.00417
Низкий

7.4 High

CVSS3