Логотип exploitDog
bind:"BDU:2018-00161" OR bind:"CVE-2017-7823"
Консоль
Логотип exploitDog

exploitDog

bind:"BDU:2018-00161" OR bind:"CVE-2017-7823"

Количество 12

Количество 12

fstec логотип

BDU:2018-00161

почти 8 лет назад

Уязвимость реализации механизма CSP браузеров Mozilla Firefox, Firefox ESR и почтового клиента Thunderbird, позволяющая нарушителю осуществлять межсайтовые сценарные атаки

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2017-7823

около 7 лет назад

The content security policy (CSP) "sandbox" directive did not create a unique origin for the document, causing it to behave as if the "allow-same-origin" keyword were always specified. This could allow a Cross-Site Scripting (XSS) attack to be launched from unsafe content. This vulnerability affects Firefox < 56, Firefox ESR < 52.4, and Thunderbird < 52.4.

CVSS3: 5.4
EPSS: Низкий
redhat логотип

CVE-2017-7823

почти 8 лет назад

The content security policy (CSP) "sandbox" directive did not create a unique origin for the document, causing it to behave as if the "allow-same-origin" keyword were always specified. This could allow a Cross-Site Scripting (XSS) attack to be launched from unsafe content. This vulnerability affects Firefox < 56, Firefox ESR < 52.4, and Thunderbird < 52.4.

CVSS3: 6.1
EPSS: Низкий
nvd логотип

CVE-2017-7823

около 7 лет назад

The content security policy (CSP) "sandbox" directive did not create a unique origin for the document, causing it to behave as if the "allow-same-origin" keyword were always specified. This could allow a Cross-Site Scripting (XSS) attack to be launched from unsafe content. This vulnerability affects Firefox < 56, Firefox ESR < 52.4, and Thunderbird < 52.4.

CVSS3: 5.4
EPSS: Низкий
debian логотип

CVE-2017-7823

около 7 лет назад

The content security policy (CSP) "sandbox" directive did not create a ...

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-hhcx-w758-8p3p

около 3 лет назад

The content security policy (CSP) "sandbox" directive did not create a unique origin for the document, causing it to behave as if the "allow-same-origin" keyword were always specified. This could allow a Cross-Site Scripting (XSS) attack to be launched from unsafe content. This vulnerability affects Firefox < 56, Firefox ESR < 52.4, and Thunderbird < 52.4.

CVSS3: 5.4
EPSS: Низкий
oracle-oval логотип

ELSA-2017-2885

почти 8 лет назад

ELSA-2017-2885: thunderbird security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2017-2831

почти 8 лет назад

ELSA-2017-2831: firefox security update (CRITICAL)

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2017:2615-1

почти 8 лет назад

Security update for Mozilla Firefox and NSS

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2017:2872-2

почти 8 лет назад

Security update for MozillaFirefox, mozilla-nss

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2017:2872-1

почти 8 лет назад

Security update for MozillaFirefox, mozilla-nss

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2017:2688-1

почти 8 лет назад

Security update for MozillaFirefox, mozilla-nss

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
fstec логотип
BDU:2018-00161

Уязвимость реализации механизма CSP браузеров Mozilla Firefox, Firefox ESR и почтового клиента Thunderbird, позволяющая нарушителю осуществлять межсайтовые сценарные атаки

CVSS3: 7.5
1%
Низкий
почти 8 лет назад
ubuntu логотип
CVE-2017-7823

The content security policy (CSP) "sandbox" directive did not create a unique origin for the document, causing it to behave as if the "allow-same-origin" keyword were always specified. This could allow a Cross-Site Scripting (XSS) attack to be launched from unsafe content. This vulnerability affects Firefox < 56, Firefox ESR < 52.4, and Thunderbird < 52.4.

CVSS3: 5.4
1%
Низкий
около 7 лет назад
redhat логотип
CVE-2017-7823

The content security policy (CSP) "sandbox" directive did not create a unique origin for the document, causing it to behave as if the "allow-same-origin" keyword were always specified. This could allow a Cross-Site Scripting (XSS) attack to be launched from unsafe content. This vulnerability affects Firefox < 56, Firefox ESR < 52.4, and Thunderbird < 52.4.

CVSS3: 6.1
1%
Низкий
почти 8 лет назад
nvd логотип
CVE-2017-7823

The content security policy (CSP) "sandbox" directive did not create a unique origin for the document, causing it to behave as if the "allow-same-origin" keyword were always specified. This could allow a Cross-Site Scripting (XSS) attack to be launched from unsafe content. This vulnerability affects Firefox < 56, Firefox ESR < 52.4, and Thunderbird < 52.4.

CVSS3: 5.4
1%
Низкий
около 7 лет назад
debian логотип
CVE-2017-7823

The content security policy (CSP) "sandbox" directive did not create a ...

CVSS3: 5.4
1%
Низкий
около 7 лет назад
github логотип
GHSA-hhcx-w758-8p3p

The content security policy (CSP) "sandbox" directive did not create a unique origin for the document, causing it to behave as if the "allow-same-origin" keyword were always specified. This could allow a Cross-Site Scripting (XSS) attack to be launched from unsafe content. This vulnerability affects Firefox < 56, Firefox ESR < 52.4, and Thunderbird < 52.4.

CVSS3: 5.4
1%
Низкий
около 3 лет назад
oracle-oval логотип
ELSA-2017-2885

ELSA-2017-2885: thunderbird security update (IMPORTANT)

почти 8 лет назад
oracle-oval логотип
ELSA-2017-2831

ELSA-2017-2831: firefox security update (CRITICAL)

почти 8 лет назад
suse-cvrf логотип
openSUSE-SU-2017:2615-1

Security update for Mozilla Firefox and NSS

почти 8 лет назад
suse-cvrf логотип
SUSE-SU-2017:2872-2

Security update for MozillaFirefox, mozilla-nss

почти 8 лет назад
suse-cvrf логотип
SUSE-SU-2017:2872-1

Security update for MozillaFirefox, mozilla-nss

почти 8 лет назад
suse-cvrf логотип
SUSE-SU-2017:2688-1

Security update for MozillaFirefox, mozilla-nss

почти 8 лет назад

Уязвимостей на страницу