Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2017-7813

Опубликовано: 11 июн. 2018
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 6.4
CVSS3: 8.2

Описание

Inside the JavaScript parser, a cast of an integer to a narrower type can result in data read from outside the buffer being parsed. This usually results in a non-exploitable crash, but can leak a limited amount of information from memory if it matches JavaScript identifier syntax. This vulnerability affects Firefox < 56.

РелизСтатусПримечание
artful

released

56.0+build6-0ubuntu1
bionic

released

56.0+build6-0ubuntu1
cosmic

released

56.0+build6-0ubuntu1
devel

released

56.0+build6-0ubuntu1
disco

released

56.0+build6-0ubuntu1
eoan

released

56.0+build6-0ubuntu1
esm-infra-legacy/trusty

DNE

trusty/esm was DNE [trusty was released [56.0+build6-0ubuntu0.14.04.1]]
esm-infra/focal

DNE

focal

released

56.0+build6-0ubuntu1
groovy

released

56.0+build6-0ubuntu1

Показывать по

РелизСтатусПримечание
artful

ignored

end of life
bionic

ignored

end of standard support, was needs-triage
cosmic

DNE

devel

DNE

disco

DNE

eoan

DNE

esm-apps/bionic

ignored

esm-infra-legacy/trusty

DNE

esm-infra/focal

DNE

focal

DNE

Показывать по

РелизСтатусПримечание
artful

not-affected

bionic

not-affected

cosmic

not-affected

devel

DNE

disco

not-affected

eoan

not-affected

esm-apps/focal

not-affected

esm-infra-legacy/trusty

DNE

esm-infra/bionic

not-affected

focal

not-affected

Показывать по

EPSS

Процентиль: 68%
0.00579
Низкий

6.4 Medium

CVSS2

8.2 High

CVSS3

Связанные уязвимости

CVSS3: 8.2
nvd
больше 7 лет назад

Inside the JavaScript parser, a cast of an integer to a narrower type can result in data read from outside the buffer being parsed. This usually results in a non-exploitable crash, but can leak a limited amount of information from memory if it matches JavaScript identifier syntax. This vulnerability affects Firefox < 56.

CVSS3: 8.2
debian
больше 7 лет назад

Inside the JavaScript parser, a cast of an integer to a narrower type ...

CVSS3: 8.2
github
больше 3 лет назад

Inside the JavaScript parser, a cast of an integer to a narrower type can result in data read from outside the buffer being parsed. This usually results in a non-exploitable crash, but can leak a limited amount of information from memory if it matches JavaScript identifier syntax. This vulnerability affects Firefox < 56.

CVSS3: 8.2
fstec
больше 8 лет назад

Уязвимость синтаксического анализатора JavaScript браузера Mozilla Firefox, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации или вызвать отказ в обслуживании

EPSS

Процентиль: 68%
0.00579
Низкий

6.4 Medium

CVSS2

8.2 High

CVSS3