Описание
The Developer Tools feature suffers from a XUL injection vulnerability due to improper sanitization of the web page source code. In the worst case, this could allow arbitrary code execution when opening a malicious page with the style editor tool. This vulnerability affects Firefox ESR < 52.3 and Firefox < 55.
Релиз | Статус | Примечание |
---|---|---|
artful | released | 55.0.2+build1-0ubuntu4 |
bionic | released | 55.0.2+build1-0ubuntu4 |
cosmic | released | 55.0.2+build1-0ubuntu4 |
devel | released | 55.0.2+build1-0ubuntu4 |
disco | released | 55.0.2+build1-0ubuntu4 |
eoan | released | 55.0.2+build1-0ubuntu4 |
esm-infra-legacy/trusty | DNE | trusty/esm was DNE [trusty was released [55.0.1+build2-0ubuntu0.14.04.2]] |
esm-infra/focal | DNE | |
focal | released | 55.0.2+build1-0ubuntu4 |
groovy | released | 55.0.2+build1-0ubuntu4 |
Показывать по
Релиз | Статус | Примечание |
---|---|---|
artful | ignored | end of life |
bionic | ignored | end of standard support, was needs-triage |
cosmic | DNE | |
devel | DNE | |
disco | DNE | |
eoan | DNE | |
esm-apps/bionic | ignored | |
esm-infra-legacy/trusty | DNE | |
esm-infra/focal | DNE | |
focal | DNE |
Показывать по
EPSS
6.8 Medium
CVSS2
8.8 High
CVSS3
Связанные уязвимости
The Developer Tools feature suffers from a XUL injection vulnerability due to improper sanitization of the web page source code. In the worst case, this could allow arbitrary code execution when opening a malicious page with the style editor tool. This vulnerability affects Firefox ESR < 52.3 and Firefox < 55.
The Developer Tools feature suffers from a XUL injection vulnerability due to improper sanitization of the web page source code. In the worst case, this could allow arbitrary code execution when opening a malicious page with the style editor tool. This vulnerability affects Firefox ESR < 52.3 and Firefox < 55.
The Developer Tools feature suffers from a XUL injection vulnerability ...
The Developer Tools feature suffers from a XUL injection vulnerability due to improper sanitization of the web page source code. In the worst case, this could allow arbitrary code execution when opening a malicious page with the style editor tool. This vulnerability affects Firefox ESR < 52.3 and Firefox < 55.
Уязвимость компонента Developer Tools браузера Mozilla Firefox ESR, позволяющая нарушителю выполнить произвольный код
EPSS
6.8 Medium
CVSS2
8.8 High
CVSS3