Описание
The HTMLSourceElement::AfterSetAttr function in Mozilla Firefox before 37.0 does not properly constrain the original data type of a casted value during the setting of a SOURCE element's attributes, which allows remote attackers to execute arbitrary code or cause a denial of service (use-after-free) via a crafted HTML document.
| Релиз | Статус | Примечание |
|---|---|---|
| devel | released | 37.0+build2-0ubuntu1 |
| esm-infra-legacy/trusty | DNE | trusty/esm was DNE [trusty was released [37.0+build2-0ubuntu0.14.04.1]] |
| lucid | ignored | end of life |
| precise | released | 37.0+build2-0ubuntu0.12.04.1 |
| trusty | released | 37.0+build2-0ubuntu0.14.04.1 |
| trusty/esm | DNE | trusty was released [37.0+build2-0ubuntu0.14.04.1] |
| upstream | released | 37.0 |
| utopic | released | 37.0+build2-0ubuntu0.14.10.1 |
Показывать по
EPSS
7.5 High
CVSS2
Связанные уязвимости
The HTMLSourceElement::AfterSetAttr function in Mozilla Firefox before 37.0 does not properly constrain the original data type of a casted value during the setting of a SOURCE element's attributes, which allows remote attackers to execute arbitrary code or cause a denial of service (use-after-free) via a crafted HTML document.
The HTMLSourceElement::AfterSetAttr function in Mozilla Firefox before 37.0 does not properly constrain the original data type of a casted value during the setting of a SOURCE element's attributes, which allows remote attackers to execute arbitrary code or cause a denial of service (use-after-free) via a crafted HTML document.
The HTMLSourceElement::AfterSetAttr function in Mozilla Firefox before ...
The HTMLSourceElement::AfterSetAttr function in Mozilla Firefox before 37.0 does not properly constrain the original data type of a casted value during the setting of a SOURCE element's attributes, which allows remote attackers to execute arbitrary code or cause a denial of service (use-after-free) via a crafted HTML document.
Уязвимость браузера Firefox, позволяющая удалённому злоумышленнику выполнить произвольный код или вызвать отказ в обслуживании
EPSS
7.5 High
CVSS2