Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2022-26382

Опубликовано: 22 дек. 2022
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS3: 4.3

Описание

While the text displayed in Autofill tooltips cannot be directly read by JavaScript, the text was rendered using page fonts. Side-channel attacks on the text by using specially crafted fonts could have lead to this text being inferred by the webpage. This vulnerability affects Firefox < 98.

РелизСтатусПримечание
bionic

released

98.0+build3-0ubuntu0.18.04.2
devel

released

1:1snap1-0ubuntu1
esm-infra-legacy/trusty

DNE

esm-infra/focal

DNE

focal

released

98.0+build3-0ubuntu0.20.04.2
impish

released

98.0+build3-0ubuntu0.21.10.2
jammy

released

1:1snap1-0ubuntu1
kinetic

released

1:1snap1-0ubuntu1
lunar

released

1:1snap1-0ubuntu1
trusty

ignored

end of standard support

Показывать по

EPSS

Процентиль: 46%
0.00236
Низкий

4.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.3
nvd
почти 3 года назад

While the text displayed in Autofill tooltips cannot be directly read by JavaScript, the text was rendered using page fonts. Side-channel attacks on the text by using specially crafted fonts could have lead to this text being inferred by the webpage. This vulnerability affects Firefox < 98.

CVSS3: 4.3
debian
почти 3 года назад

While the text displayed in Autofill tooltips cannot be directly read ...

CVSS3: 4.3
github
почти 3 года назад

While the text displayed in Autofill tooltips cannot be directly read by JavaScript, the text was rendered using page fonts. Side-channel attacks on the text by using specially crafted fonts could have lead to this text being inferred by the webpage. This vulnerability affects Firefox < 98.

CVSS3: 4.3
fstec
больше 3 лет назад

Уязвимость браузера Mozilla Firefox, связанная с отсутствием защиты служебных данных, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

EPSS

Процентиль: 46%
0.00236
Низкий

4.3 Medium

CVSS3

Уязвимость CVE-2022-26382