Логотип exploitDog
bind:CVE-2020-15682
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2020-15682

Количество 5

Количество 5

ubuntu логотип

CVE-2020-15682

больше 5 лет назад

When a link to an external protocol was clicked, a prompt was presented that allowed the user to choose what application to open it in. An attacker could induce that prompt to be associated with an origin they didn't control, resulting in a spoofing attack. This was fixed by changing external protocol prompts to be tab-modal while also ensuring they could not be incorrectly associated with a different origin. This vulnerability affects Firefox < 82.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2020-15682

больше 5 лет назад

When a link to an external protocol was clicked, a prompt was presented that allowed the user to choose what application to open it in. An attacker could induce that prompt to be associated with an origin they didn't control, resulting in a spoofing attack. This was fixed by changing external protocol prompts to be tab-modal while also ensuring they could not be incorrectly associated with a different origin. This vulnerability affects Firefox < 82.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2020-15682

больше 5 лет назад

When a link to an external protocol was clicked, a prompt was presente ...

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-hx45-gw2r-332x

больше 3 лет назад

When a link to an external protocol was clicked, a prompt was presented that allowed the user to choose what application to open it in. An attacker could induce that prompt to be associated with an origin they didn't control, resulting in a spoofing attack. This was fixed by changing external protocol prompts to be tab-modal while also ensuring they could not be incorrectly associated with a different origin. This vulnerability affects Firefox < 82.

EPSS: Низкий
fstec логотип

BDU:2022-05932

больше 5 лет назад

Уязвимость браузера Mozilla Firefox, связанная с недостатком в механизме подтверждения источника данных, позволяющая нарушителю проводить спуфинг-атаки

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2020-15682

When a link to an external protocol was clicked, a prompt was presented that allowed the user to choose what application to open it in. An attacker could induce that prompt to be associated with an origin they didn't control, resulting in a spoofing attack. This was fixed by changing external protocol prompts to be tab-modal while also ensuring they could not be incorrectly associated with a different origin. This vulnerability affects Firefox < 82.

CVSS3: 6.5
0%
Низкий
больше 5 лет назад
nvd логотип
CVE-2020-15682

When a link to an external protocol was clicked, a prompt was presented that allowed the user to choose what application to open it in. An attacker could induce that prompt to be associated with an origin they didn't control, resulting in a spoofing attack. This was fixed by changing external protocol prompts to be tab-modal while also ensuring they could not be incorrectly associated with a different origin. This vulnerability affects Firefox < 82.

CVSS3: 6.5
0%
Низкий
больше 5 лет назад
debian логотип
CVE-2020-15682

When a link to an external protocol was clicked, a prompt was presente ...

CVSS3: 6.5
0%
Низкий
больше 5 лет назад
github логотип
GHSA-hx45-gw2r-332x

When a link to an external protocol was clicked, a prompt was presented that allowed the user to choose what application to open it in. An attacker could induce that prompt to be associated with an origin they didn't control, resulting in a spoofing attack. This was fixed by changing external protocol prompts to be tab-modal while also ensuring they could not be incorrectly associated with a different origin. This vulnerability affects Firefox < 82.

0%
Низкий
больше 3 лет назад
fstec логотип
BDU:2022-05932

Уязвимость браузера Mozilla Firefox, связанная с недостатком в механизме подтверждения источника данных, позволяющая нарушителю проводить спуфинг-атаки

CVSS3: 6.5
0%
Низкий
больше 5 лет назад

Уязвимостей на страницу