Логотип exploitDog
bind:"GHSA-mxf2-hfjf-3p4q" OR bind:"CVE-2017-7768"
Консоль
Логотип exploitDog

exploitDog

bind:"GHSA-mxf2-hfjf-3p4q" OR bind:"CVE-2017-7768"

Количество 7

Количество 7

github логотип

GHSA-mxf2-hfjf-3p4q

больше 3 лет назад

The Mozilla Maintenance Service can be invoked by an unprivileged user to read 32 bytes of any arbitrary file on the local system by convincing the service that it is reading a status file provided by the Mozilla Windows Updater. The Mozilla Maintenance Service executes with privileged access, bypassing system protections against unprivileged users. Note: This attack requires local system access and only affects Windows. Other operating systems are not affected. This vulnerability affects Firefox ESR < 52.2 and Firefox < 54.

CVSS3: 5.5
EPSS: Низкий
ubuntu логотип

CVE-2017-7768

больше 7 лет назад

The Mozilla Maintenance Service can be invoked by an unprivileged user to read 32 bytes of any arbitrary file on the local system by convincing the service that it is reading a status file provided by the Mozilla Windows Updater. The Mozilla Maintenance Service executes with privileged access, bypassing system protections against unprivileged users. Note: This attack requires local system access and only affects Windows. Other operating systems are not affected. This vulnerability affects Firefox ESR < 52.2 and Firefox < 54.

CVSS3: 5.5
EPSS: Низкий
nvd логотип

CVE-2017-7768

больше 7 лет назад

The Mozilla Maintenance Service can be invoked by an unprivileged user to read 32 bytes of any arbitrary file on the local system by convincing the service that it is reading a status file provided by the Mozilla Windows Updater. The Mozilla Maintenance Service executes with privileged access, bypassing system protections against unprivileged users. Note: This attack requires local system access and only affects Windows. Other operating systems are not affected. This vulnerability affects Firefox ESR < 52.2 and Firefox < 54.

CVSS3: 5.5
EPSS: Низкий
debian логотип

CVE-2017-7768

больше 7 лет назад

The Mozilla Maintenance Service can be invoked by an unprivileged user ...

CVSS3: 5.5
EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2017:1620-1

больше 8 лет назад

Security update for Mozilla based packages

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2017:1669-1

больше 8 лет назад

Security update for MozillaFirefox, MozillaFirefox-branding-SLE

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2017:2235-1

больше 8 лет назад

Security update for MozillaFirefox, MozillaFirefox-branding-SLED, firefox-gcc5, mozilla-nss

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-mxf2-hfjf-3p4q

The Mozilla Maintenance Service can be invoked by an unprivileged user to read 32 bytes of any arbitrary file on the local system by convincing the service that it is reading a status file provided by the Mozilla Windows Updater. The Mozilla Maintenance Service executes with privileged access, bypassing system protections against unprivileged users. Note: This attack requires local system access and only affects Windows. Other operating systems are not affected. This vulnerability affects Firefox ESR < 52.2 and Firefox < 54.

CVSS3: 5.5
0%
Низкий
больше 3 лет назад
ubuntu логотип
CVE-2017-7768

The Mozilla Maintenance Service can be invoked by an unprivileged user to read 32 bytes of any arbitrary file on the local system by convincing the service that it is reading a status file provided by the Mozilla Windows Updater. The Mozilla Maintenance Service executes with privileged access, bypassing system protections against unprivileged users. Note: This attack requires local system access and only affects Windows. Other operating systems are not affected. This vulnerability affects Firefox ESR < 52.2 and Firefox < 54.

CVSS3: 5.5
0%
Низкий
больше 7 лет назад
nvd логотип
CVE-2017-7768

The Mozilla Maintenance Service can be invoked by an unprivileged user to read 32 bytes of any arbitrary file on the local system by convincing the service that it is reading a status file provided by the Mozilla Windows Updater. The Mozilla Maintenance Service executes with privileged access, bypassing system protections against unprivileged users. Note: This attack requires local system access and only affects Windows. Other operating systems are not affected. This vulnerability affects Firefox ESR < 52.2 and Firefox < 54.

CVSS3: 5.5
0%
Низкий
больше 7 лет назад
debian логотип
CVE-2017-7768

The Mozilla Maintenance Service can be invoked by an unprivileged user ...

CVSS3: 5.5
0%
Низкий
больше 7 лет назад
suse-cvrf логотип
openSUSE-SU-2017:1620-1

Security update for Mozilla based packages

больше 8 лет назад
suse-cvrf логотип
SUSE-SU-2017:1669-1

Security update for MozillaFirefox, MozillaFirefox-branding-SLE

больше 8 лет назад
suse-cvrf логотип
SUSE-SU-2017:2235-1

Security update for MozillaFirefox, MozillaFirefox-branding-SLED, firefox-gcc5, mozilla-nss

больше 8 лет назад

Уязвимостей на страницу