Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 24

Количество 24

ubuntu логотип

CVE-2019-11711

около 7 лет назад

When an inner window is reused, it does not consider the use of document.domain for cross-origin protections. If pages on different subdomains ever cooperatively use document.domain, then either page can abuse this to inject script into arbitrary pages on the other subdomain, even those that did not use document.domain to relax their origin security. This vulnerability affects Firefox ESR < 60.8, Firefox < 68, and Thunderbird < 60.8.

CVSS3: 8.8
EPSS: Низкий
redhat логотип

CVE-2019-11711

около 7 лет назад

When an inner window is reused, it does not consider the use of document.domain for cross-origin protections. If pages on different subdomains ever cooperatively use document.domain, then either page can abuse this to inject script into arbitrary pages on the other subdomain, even those that did not use document.domain to relax their origin security. This vulnerability affects Firefox ESR < 60.8, Firefox < 68, and Thunderbird < 60.8.

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2019-11711

около 7 лет назад

When an inner window is reused, it does not consider the use of document.domain for cross-origin protections. If pages on different subdomains ever cooperatively use document.domain, then either page can abuse this to inject script into arbitrary pages on the other subdomain, even those that did not use document.domain to relax their origin security. This vulnerability affects Firefox ESR < 60.8, Firefox < 68, and Thunderbird < 60.8.

CVSS3: 8.8
EPSS: Низкий
debian логотип

CVE-2019-11711

около 7 лет назад

When an inner window is reused, it does not consider the use of docume ...

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3cqf-mfjf-xv44

около 4 лет назад

When an inner window is reused, it does not consider the use of document.domain for cross-origin protections. If pages on different subdomains ever cooperatively use document.domain, then either page can abuse this to inject script into arbitrary pages on the other subdomain, even those that did not use document.domain to relax their origin security. This vulnerability affects Firefox ESR < 60.8, Firefox < 68, and Thunderbird < 60.8.

CVSS3: 8.8
EPSS: Низкий
fstec логотип

BDU:2019-02935

около 7 лет назад

Уязвимость компонента document.domain браузеров Firefox ESR, Firefox и почтового клиента Thunderbird, позволяющая нарушителю осуществить межсайтовую сценарную атаку

CVSS3: 8.8
EPSS: Низкий
oracle-oval логотип

ELSA-2019-1799

около 7 лет назад

ELSA-2019-1799: thunderbird security and bug fix update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2019-1777

около 7 лет назад

ELSA-2019-1777: thunderbird security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2019-1775

около 7 лет назад

ELSA-2019-1775: thunderbird security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2019-1765

около 7 лет назад

ELSA-2019-1765: firefox security update (CRITICAL)

EPSS: Низкий
oracle-oval логотип

ELSA-2019-1764

около 7 лет назад

ELSA-2019-1764: firefox security update (CRITICAL)

EPSS: Низкий
oracle-oval логотип

ELSA-2019-1763

около 7 лет назад

ELSA-2019-1763: firefox security update (CRITICAL)

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2019:1813-1

около 7 лет назад

Security update for MozillaThunderbird

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2019:1811-1

около 7 лет назад

Security update for MozillaFirefox

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2019:1782-1

около 7 лет назад

Security update for MozillaFirefox

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2019:1960-1

около 7 лет назад

Security update for MozillaThunderbird

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2019:1869-1

около 7 лет назад

Security update for MozillaFirefox

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2019:1861-1

около 7 лет назад

Security update for MozillaFirefox

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2019:14124-1

около 7 лет назад

Security update for MozillaFirefox

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2019:2249-1

почти 7 лет назад

Security update for MozillaThunderbird

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2019-11711

When an inner window is reused, it does not consider the use of document.domain for cross-origin protections. If pages on different subdomains ever cooperatively use document.domain, then either page can abuse this to inject script into arbitrary pages on the other subdomain, even those that did not use document.domain to relax their origin security. This vulnerability affects Firefox ESR < 60.8, Firefox < 68, and Thunderbird < 60.8.

CVSS3: 8.8
2%
Низкий
около 7 лет назад
redhat логотип
CVE-2019-11711

When an inner window is reused, it does not consider the use of document.domain for cross-origin protections. If pages on different subdomains ever cooperatively use document.domain, then either page can abuse this to inject script into arbitrary pages on the other subdomain, even those that did not use document.domain to relax their origin security. This vulnerability affects Firefox ESR < 60.8, Firefox < 68, and Thunderbird < 60.8.

CVSS3: 8.8
2%
Низкий
около 7 лет назад
nvd логотип
CVE-2019-11711

When an inner window is reused, it does not consider the use of document.domain for cross-origin protections. If pages on different subdomains ever cooperatively use document.domain, then either page can abuse this to inject script into arbitrary pages on the other subdomain, even those that did not use document.domain to relax their origin security. This vulnerability affects Firefox ESR < 60.8, Firefox < 68, and Thunderbird < 60.8.

CVSS3: 8.8
2%
Низкий
около 7 лет назад
debian логотип
CVE-2019-11711

When an inner window is reused, it does not consider the use of docume ...

CVSS3: 8.8
2%
Низкий
около 7 лет назад
github логотип
GHSA-3cqf-mfjf-xv44

When an inner window is reused, it does not consider the use of document.domain for cross-origin protections. If pages on different subdomains ever cooperatively use document.domain, then either page can abuse this to inject script into arbitrary pages on the other subdomain, even those that did not use document.domain to relax their origin security. This vulnerability affects Firefox ESR < 60.8, Firefox < 68, and Thunderbird < 60.8.

CVSS3: 8.8
2%
Низкий
около 4 лет назад
fstec логотип
BDU:2019-02935

Уязвимость компонента document.domain браузеров Firefox ESR, Firefox и почтового клиента Thunderbird, позволяющая нарушителю осуществить межсайтовую сценарную атаку

CVSS3: 8.8
2%
Низкий
около 7 лет назад
oracle-oval логотип
ELSA-2019-1799

ELSA-2019-1799: thunderbird security and bug fix update (IMPORTANT)

около 7 лет назад
oracle-oval логотип
ELSA-2019-1777

ELSA-2019-1777: thunderbird security update (IMPORTANT)

около 7 лет назад
oracle-oval логотип
ELSA-2019-1775

ELSA-2019-1775: thunderbird security update (IMPORTANT)

около 7 лет назад
oracle-oval логотип
ELSA-2019-1765

ELSA-2019-1765: firefox security update (CRITICAL)

около 7 лет назад
oracle-oval логотип
ELSA-2019-1764

ELSA-2019-1764: firefox security update (CRITICAL)

около 7 лет назад
oracle-oval логотип
ELSA-2019-1763

ELSA-2019-1763: firefox security update (CRITICAL)

около 7 лет назад
suse-cvrf логотип
openSUSE-SU-2019:1813-1

Security update for MozillaThunderbird

около 7 лет назад
suse-cvrf логотип
openSUSE-SU-2019:1811-1

Security update for MozillaFirefox

около 7 лет назад
suse-cvrf логотип
openSUSE-SU-2019:1782-1

Security update for MozillaFirefox

около 7 лет назад
suse-cvrf логотип
SUSE-SU-2019:1960-1

Security update for MozillaThunderbird

около 7 лет назад
suse-cvrf логотип
SUSE-SU-2019:1869-1

Security update for MozillaFirefox

около 7 лет назад
suse-cvrf логотип
SUSE-SU-2019:1861-1

Security update for MozillaFirefox

около 7 лет назад
suse-cvrf логотип
SUSE-SU-2019:14124-1

Security update for MozillaFirefox

около 7 лет назад
suse-cvrf логотип
openSUSE-SU-2019:2249-1

Security update for MozillaThunderbird

почти 7 лет назад

Уязвимостей на страницу

exploitDog - Комплексное решение для обнаружения, оценки и устранения уязвимостей.