Логотип exploitDog
bind:"GHSA-92cf-2847-r49w" OR bind:"CVE-2017-5407"
Консоль
Логотип exploitDog

exploitDog

bind:"GHSA-92cf-2847-r49w" OR bind:"CVE-2017-5407"

Количество 12

Количество 12

github логотип

GHSA-92cf-2847-r49w

больше 3 лет назад

Using SVG filters that don't use the fixed point math implementation on a target iframe, a malicious page can extract pixel values from a targeted user. This can be used to extract history information and read text values across domains. This violates same-origin policy and leads to information disclosure. This vulnerability affects Firefox < 52, Firefox ESR < 45.8, Thunderbird < 52, and Thunderbird < 45.8.

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2017-5407

больше 7 лет назад

Using SVG filters that don't use the fixed point math implementation on a target iframe, a malicious page can extract pixel values from a targeted user. This can be used to extract history information and read text values across domains. This violates same-origin policy and leads to information disclosure. This vulnerability affects Firefox < 52, Firefox ESR < 45.8, Thunderbird < 52, and Thunderbird < 45.8.

CVSS3: 6.5
EPSS: Низкий
redhat логотип

CVE-2017-5407

больше 8 лет назад

Using SVG filters that don't use the fixed point math implementation on a target iframe, a malicious page can extract pixel values from a targeted user. This can be used to extract history information and read text values across domains. This violates same-origin policy and leads to information disclosure. This vulnerability affects Firefox < 52, Firefox ESR < 45.8, Thunderbird < 52, and Thunderbird < 45.8.

CVSS3: 6.1
EPSS: Низкий
nvd логотип

CVE-2017-5407

больше 7 лет назад

Using SVG filters that don't use the fixed point math implementation on a target iframe, a malicious page can extract pixel values from a targeted user. This can be used to extract history information and read text values across domains. This violates same-origin policy and leads to information disclosure. This vulnerability affects Firefox < 52, Firefox ESR < 45.8, Thunderbird < 52, and Thunderbird < 45.8.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2017-5407

больше 7 лет назад

Using SVG filters that don't use the fixed point math implementation o ...

CVSS3: 6.5
EPSS: Низкий
oracle-oval логотип

ELSA-2017-0498

больше 8 лет назад

ELSA-2017-0498: thunderbird security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2017-0461

больше 8 лет назад

ELSA-2017-0461: firefox security update (CRITICAL)

EPSS: Низкий
oracle-oval логотип

ELSA-2017-0459

больше 8 лет назад

ELSA-2017-0459: firefox security update (CRITICAL)

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2017:0732-1

больше 8 лет назад

Security update for MozillaFirefox

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2017:0714-1

больше 8 лет назад

Security update for MozillaFirefox

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2017:0690-1

больше 8 лет назад

Security update for MozillaFirefox, mozilla-nss

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2017:1196-1

больше 8 лет назад

Security update for MozillaThunderbird

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-92cf-2847-r49w

Using SVG filters that don't use the fixed point math implementation on a target iframe, a malicious page can extract pixel values from a targeted user. This can be used to extract history information and read text values across domains. This violates same-origin policy and leads to information disclosure. This vulnerability affects Firefox < 52, Firefox ESR < 45.8, Thunderbird < 52, and Thunderbird < 45.8.

CVSS3: 6.5
1%
Низкий
больше 3 лет назад
ubuntu логотип
CVE-2017-5407

Using SVG filters that don't use the fixed point math implementation on a target iframe, a malicious page can extract pixel values from a targeted user. This can be used to extract history information and read text values across domains. This violates same-origin policy and leads to information disclosure. This vulnerability affects Firefox < 52, Firefox ESR < 45.8, Thunderbird < 52, and Thunderbird < 45.8.

CVSS3: 6.5
1%
Низкий
больше 7 лет назад
redhat логотип
CVE-2017-5407

Using SVG filters that don't use the fixed point math implementation on a target iframe, a malicious page can extract pixel values from a targeted user. This can be used to extract history information and read text values across domains. This violates same-origin policy and leads to information disclosure. This vulnerability affects Firefox < 52, Firefox ESR < 45.8, Thunderbird < 52, and Thunderbird < 45.8.

CVSS3: 6.1
1%
Низкий
больше 8 лет назад
nvd логотип
CVE-2017-5407

Using SVG filters that don't use the fixed point math implementation on a target iframe, a malicious page can extract pixel values from a targeted user. This can be used to extract history information and read text values across domains. This violates same-origin policy and leads to information disclosure. This vulnerability affects Firefox < 52, Firefox ESR < 45.8, Thunderbird < 52, and Thunderbird < 45.8.

CVSS3: 6.5
1%
Низкий
больше 7 лет назад
debian логотип
CVE-2017-5407

Using SVG filters that don't use the fixed point math implementation o ...

CVSS3: 6.5
1%
Низкий
больше 7 лет назад
oracle-oval логотип
ELSA-2017-0498

ELSA-2017-0498: thunderbird security update (IMPORTANT)

больше 8 лет назад
oracle-oval логотип
ELSA-2017-0461

ELSA-2017-0461: firefox security update (CRITICAL)

больше 8 лет назад
oracle-oval логотип
ELSA-2017-0459

ELSA-2017-0459: firefox security update (CRITICAL)

больше 8 лет назад
suse-cvrf логотип
SUSE-SU-2017:0732-1

Security update for MozillaFirefox

больше 8 лет назад
suse-cvrf логотип
SUSE-SU-2017:0714-1

Security update for MozillaFirefox

больше 8 лет назад
suse-cvrf логотип
openSUSE-SU-2017:0690-1

Security update for MozillaFirefox, mozilla-nss

больше 8 лет назад
suse-cvrf логотип
openSUSE-SU-2017:1196-1

Security update for MozillaThunderbird

больше 8 лет назад

Уязвимостей на страницу