Логотип exploitDog
bind:"GHSA-w7p8-wf2r-rw5h" OR bind:"CVE-2020-26951"
Консоль
Логотип exploitDog

exploitDog

bind:"GHSA-w7p8-wf2r-rw5h" OR bind:"CVE-2020-26951"

Количество 22

Количество 22

github логотип

GHSA-w7p8-wf2r-rw5h

больше 3 лет назад

A parsing and event loading mismatch in Firefox's SVG code could have allowed load events to fire, even after sanitization. An attacker already capable of exploiting an XSS vulnerability in privileged internal pages could have used this attack to bypass our built-in sanitizer. This vulnerability affects Firefox < 83, Firefox ESR < 78.5, and Thunderbird < 78.5.

EPSS: Низкий
ubuntu логотип

CVE-2020-26951

около 5 лет назад

A parsing and event loading mismatch in Firefox's SVG code could have allowed load events to fire, even after sanitization. An attacker already capable of exploiting an XSS vulnerability in privileged internal pages could have used this attack to bypass our built-in sanitizer. This vulnerability affects Firefox < 83, Firefox ESR < 78.5, and Thunderbird < 78.5.

CVSS3: 6.1
EPSS: Низкий
redhat логотип

CVE-2020-26951

около 5 лет назад

A parsing and event loading mismatch in Firefox's SVG code could have allowed load events to fire, even after sanitization. An attacker already capable of exploiting an XSS vulnerability in privileged internal pages could have used this attack to bypass our built-in sanitizer. This vulnerability affects Firefox < 83, Firefox ESR < 78.5, and Thunderbird < 78.5.

CVSS3: 6.1
EPSS: Низкий
nvd логотип

CVE-2020-26951

около 5 лет назад

A parsing and event loading mismatch in Firefox's SVG code could have allowed load events to fire, even after sanitization. An attacker already capable of exploiting an XSS vulnerability in privileged internal pages could have used this attack to bypass our built-in sanitizer. This vulnerability affects Firefox < 83, Firefox ESR < 78.5, and Thunderbird < 78.5.

CVSS3: 6.1
EPSS: Низкий
debian логотип

CVE-2020-26951

около 5 лет назад

A parsing and event loading mismatch in Firefox's SVG code could have ...

CVSS3: 6.1
EPSS: Низкий
fstec логотип

BDU:2020-05537

около 5 лет назад

Уязвимость синтаксического анализа и загрузки событий в коде SVG веб-браузера Firefox и почтового клиента Thunderbird, позволяющая нарушителю проводить межсайтовые сценарные атаки (XSS)

CVSS3: 7.5
EPSS: Низкий
oracle-oval логотип

ELSA-2020-5257

около 5 лет назад

ELSA-2020-5257: firefox security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2020-5239

около 5 лет назад

ELSA-2020-5239: firefox security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2020-5238

около 5 лет назад

ELSA-2020-5238: thunderbird security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2020-5237

около 5 лет назад

ELSA-2020-5237: firefox security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2020-5236

около 5 лет назад

ELSA-2020-5236: thunderbird security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2020-5235

около 5 лет назад

ELSA-2020-5235: thunderbird security update (IMPORTANT)

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2020:2315-1

около 5 лет назад

Security update for MozillaFirefox

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2020:2187-1

около 5 лет назад

Security update for MozillaThunderbird

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2020:2096-1

около 5 лет назад

Security update for MozillaThunderbird

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2020:2031-1

около 5 лет назад

Security update for MozillaFirefox

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2020:2020-1

около 5 лет назад

Security update for MozillaFirefox

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2020:3548-1

около 5 лет назад

Security update for MozillaFirefox

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2020:3528-1

около 5 лет назад

Security update for MozillaThunderbird

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2020:3458-1

около 5 лет назад

Security update for MozillaFirefox

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-w7p8-wf2r-rw5h

A parsing and event loading mismatch in Firefox's SVG code could have allowed load events to fire, even after sanitization. An attacker already capable of exploiting an XSS vulnerability in privileged internal pages could have used this attack to bypass our built-in sanitizer. This vulnerability affects Firefox < 83, Firefox ESR < 78.5, and Thunderbird < 78.5.

0%
Низкий
больше 3 лет назад
ubuntu логотип
CVE-2020-26951

A parsing and event loading mismatch in Firefox's SVG code could have allowed load events to fire, even after sanitization. An attacker already capable of exploiting an XSS vulnerability in privileged internal pages could have used this attack to bypass our built-in sanitizer. This vulnerability affects Firefox < 83, Firefox ESR < 78.5, and Thunderbird < 78.5.

CVSS3: 6.1
0%
Низкий
около 5 лет назад
redhat логотип
CVE-2020-26951

A parsing and event loading mismatch in Firefox's SVG code could have allowed load events to fire, even after sanitization. An attacker already capable of exploiting an XSS vulnerability in privileged internal pages could have used this attack to bypass our built-in sanitizer. This vulnerability affects Firefox < 83, Firefox ESR < 78.5, and Thunderbird < 78.5.

CVSS3: 6.1
0%
Низкий
около 5 лет назад
nvd логотип
CVE-2020-26951

A parsing and event loading mismatch in Firefox's SVG code could have allowed load events to fire, even after sanitization. An attacker already capable of exploiting an XSS vulnerability in privileged internal pages could have used this attack to bypass our built-in sanitizer. This vulnerability affects Firefox < 83, Firefox ESR < 78.5, and Thunderbird < 78.5.

CVSS3: 6.1
0%
Низкий
около 5 лет назад
debian логотип
CVE-2020-26951

A parsing and event loading mismatch in Firefox's SVG code could have ...

CVSS3: 6.1
0%
Низкий
около 5 лет назад
fstec логотип
BDU:2020-05537

Уязвимость синтаксического анализа и загрузки событий в коде SVG веб-браузера Firefox и почтового клиента Thunderbird, позволяющая нарушителю проводить межсайтовые сценарные атаки (XSS)

CVSS3: 7.5
0%
Низкий
около 5 лет назад
oracle-oval логотип
ELSA-2020-5257

ELSA-2020-5257: firefox security update (IMPORTANT)

около 5 лет назад
oracle-oval логотип
ELSA-2020-5239

ELSA-2020-5239: firefox security update (IMPORTANT)

около 5 лет назад
oracle-oval логотип
ELSA-2020-5238

ELSA-2020-5238: thunderbird security update (IMPORTANT)

около 5 лет назад
oracle-oval логотип
ELSA-2020-5237

ELSA-2020-5237: firefox security update (IMPORTANT)

около 5 лет назад
oracle-oval логотип
ELSA-2020-5236

ELSA-2020-5236: thunderbird security update (IMPORTANT)

около 5 лет назад
oracle-oval логотип
ELSA-2020-5235

ELSA-2020-5235: thunderbird security update (IMPORTANT)

около 5 лет назад
suse-cvrf логотип
openSUSE-SU-2020:2315-1

Security update for MozillaFirefox

около 5 лет назад
suse-cvrf логотип
openSUSE-SU-2020:2187-1

Security update for MozillaThunderbird

около 5 лет назад
suse-cvrf логотип
openSUSE-SU-2020:2096-1

Security update for MozillaThunderbird

около 5 лет назад
suse-cvrf логотип
openSUSE-SU-2020:2031-1

Security update for MozillaFirefox

около 5 лет назад
suse-cvrf логотип
openSUSE-SU-2020:2020-1

Security update for MozillaFirefox

около 5 лет назад
suse-cvrf логотип
SUSE-SU-2020:3548-1

Security update for MozillaFirefox

около 5 лет назад
suse-cvrf логотип
SUSE-SU-2020:3528-1

Security update for MozillaThunderbird

около 5 лет назад
suse-cvrf логотип
SUSE-SU-2020:3458-1

Security update for MozillaFirefox

около 5 лет назад

Уязвимостей на страницу