Описание
The Firefox Health Reports (aka FHR or about:healthreport) feature in Mozilla Firefox before 46.0 does not properly restrict the origin of events, which makes it easier for remote attackers to modify sharing preferences by leveraging access to the remote-report IFRAME element.
| Релиз | Статус | Примечание |
|---|---|---|
| devel | released | 46.0.1+build1-0ubuntu1 |
| esm-infra-legacy/trusty | DNE | trusty/esm was DNE [trusty was released [46.0+build5-0ubuntu0.14.04.2]] |
| precise | released | 46.0+build5-0ubuntu0.12.04.2 |
| trusty | released | 46.0+build5-0ubuntu0.14.04.2 |
| trusty/esm | DNE | trusty was released [46.0+build5-0ubuntu0.14.04.2] |
| upstream | released | 46.0 |
| vivid/stable-phone-overlay | DNE | |
| vivid/ubuntu-core | DNE | |
| wily | released | 46.0+build5-0ubuntu0.15.10.2 |
| xenial | released | 46.0+build5-0ubuntu0.16.04.2 |
Показывать по
| Релиз | Статус | Примечание |
|---|---|---|
| devel | not-affected | |
| esm-infra-legacy/trusty | DNE | trusty/esm was DNE [trusty was not-affected] |
| precise | not-affected | |
| trusty | not-affected | |
| trusty/esm | DNE | trusty was not-affected |
| upstream | not-affected | |
| vivid/stable-phone-overlay | DNE | |
| vivid/ubuntu-core | DNE | |
| wily | not-affected | |
| xenial | not-affected |
Показывать по
EPSS
4.3 Medium
CVSS2
4.3 Medium
CVSS3
Связанные уязвимости
The Firefox Health Reports (aka FHR or about:healthreport) feature in Mozilla Firefox before 46.0 does not properly restrict the origin of events, which makes it easier for remote attackers to modify sharing preferences by leveraging access to the remote-report IFRAME element.
The Firefox Health Reports (aka FHR or about:healthreport) feature in Mozilla Firefox before 46.0 does not properly restrict the origin of events, which makes it easier for remote attackers to modify sharing preferences by leveraging access to the remote-report IFRAME element.
The Firefox Health Reports (aka FHR or about:healthreport) feature in ...
The Firefox Health Reports (aka FHR or about:healthreport) feature in Mozilla Firefox before 46.0 does not properly restrict the origin of events, which makes it easier for remote attackers to modify sharing preferences by leveraging access to the remote-report IFRAME element.
Уязвимость браузера Firefox, позволяющая нарушителю внести изменения в настройки общего доступа
EPSS
4.3 Medium
CVSS2
4.3 Medium
CVSS3