Количество 24
Количество 24
BDU:2020-00723
Уязвимость веб-браузеров Firefox, Firefox ESR и программы для работы с электронной почтой Thunderbird, связанная с отсутствием защиты служебных данных, позволяющая нарушителю получить несанкционированный доступ к конфиденциальным данным
CVE-2019-11730
A vulnerability exists where if a user opens a locally saved HTML file, this file can use file: URIs to access other files in the same directory or sub-directories if the names are known or guessed. The Fetch API can then be used to read the contents of any files stored in these directories and they may uploaded to a server. It was demonstrated that in combination with a popular Android messaging app, if a malicious HTML attachment is sent to a user and they opened that attachment in Firefox, due to that app's predictable pattern for locally-saved file names, it is possible to read attachments the victim received from other correspondents. This vulnerability affects Firefox ESR < 60.8, Firefox < 68, and Thunderbird < 60.8.
CVE-2019-11730
A vulnerability exists where if a user opens a locally saved HTML file, this file can use file: URIs to access other files in the same directory or sub-directories if the names are known or guessed. The Fetch API can then be used to read the contents of any files stored in these directories and they may uploaded to a server. It was demonstrated that in combination with a popular Android messaging app, if a malicious HTML attachment is sent to a user and they opened that attachment in Firefox, due to that app's predictable pattern for locally-saved file names, it is possible to read attachments the victim received from other correspondents. This vulnerability affects Firefox ESR < 60.8, Firefox < 68, and Thunderbird < 60.8.
CVE-2019-11730
A vulnerability exists where if a user opens a locally saved HTML file, this file can use file: URIs to access other files in the same directory or sub-directories if the names are known or guessed. The Fetch API can then be used to read the contents of any files stored in these directories and they may uploaded to a server. It was demonstrated that in combination with a popular Android messaging app, if a malicious HTML attachment is sent to a user and they opened that attachment in Firefox, due to that app's predictable pattern for locally-saved file names, it is possible to read attachments the victim received from other correspondents. This vulnerability affects Firefox ESR < 60.8, Firefox < 68, and Thunderbird < 60.8.
CVE-2019-11730
A vulnerability exists where if a user opens a locally saved HTML file ...
GHSA-353x-8rf5-m26c
A vulnerability exists where if a user opens a locally saved HTML file, this file can use file: URIs to access other files in the same directory or sub-directories if the names are known or guessed. The Fetch API can then be used to read the contents of any files stored in these directories and they may uploaded to a server. It was demonstrated that in combination with a popular Android messaging app, if a malicious HTML attachment is sent to a user and they opened that attachment in Firefox, due to that app's predictable pattern for locally-saved file names, it is possible to read attachments the victim received from other correspondents. This vulnerability affects Firefox ESR < 60.8, Firefox < 68, and Thunderbird < 60.8.
ELSA-2019-1799
ELSA-2019-1799: thunderbird security and bug fix update (IMPORTANT)
ELSA-2019-1777
ELSA-2019-1777: thunderbird security update (IMPORTANT)
ELSA-2019-1775
ELSA-2019-1775: thunderbird security update (IMPORTANT)
ELSA-2019-1765
ELSA-2019-1765: firefox security update (CRITICAL)
ELSA-2019-1764
ELSA-2019-1764: firefox security update (CRITICAL)
ELSA-2019-1763
ELSA-2019-1763: firefox security update (CRITICAL)
openSUSE-SU-2019:1813-1
Security update for MozillaThunderbird
openSUSE-SU-2019:1811-1
Security update for MozillaFirefox
openSUSE-SU-2019:1782-1
Security update for MozillaFirefox
SUSE-SU-2019:1960-1
Security update for MozillaThunderbird
SUSE-SU-2019:1869-1
Security update for MozillaFirefox
SUSE-SU-2019:1861-1
Security update for MozillaFirefox
SUSE-SU-2019:14124-1
Security update for MozillaFirefox
openSUSE-SU-2019:2249-1
Security update for MozillaThunderbird
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
BDU:2020-00723 Уязвимость веб-браузеров Firefox, Firefox ESR и программы для работы с электронной почтой Thunderbird, связанная с отсутствием защиты служебных данных, позволяющая нарушителю получить несанкционированный доступ к конфиденциальным данным | CVSS3: 6.5 | 20% Средний | больше 6 лет назад | |
CVE-2019-11730 A vulnerability exists where if a user opens a locally saved HTML file, this file can use file: URIs to access other files in the same directory or sub-directories if the names are known or guessed. The Fetch API can then be used to read the contents of any files stored in these directories and they may uploaded to a server. It was demonstrated that in combination with a popular Android messaging app, if a malicious HTML attachment is sent to a user and they opened that attachment in Firefox, due to that app's predictable pattern for locally-saved file names, it is possible to read attachments the victim received from other correspondents. This vulnerability affects Firefox ESR < 60.8, Firefox < 68, and Thunderbird < 60.8. | CVSS3: 6.5 | 20% Средний | больше 6 лет назад | |
CVE-2019-11730 A vulnerability exists where if a user opens a locally saved HTML file, this file can use file: URIs to access other files in the same directory or sub-directories if the names are known or guessed. The Fetch API can then be used to read the contents of any files stored in these directories and they may uploaded to a server. It was demonstrated that in combination with a popular Android messaging app, if a malicious HTML attachment is sent to a user and they opened that attachment in Firefox, due to that app's predictable pattern for locally-saved file names, it is possible to read attachments the victim received from other correspondents. This vulnerability affects Firefox ESR < 60.8, Firefox < 68, and Thunderbird < 60.8. | CVSS3: 6.1 | 20% Средний | больше 6 лет назад | |
CVE-2019-11730 A vulnerability exists where if a user opens a locally saved HTML file, this file can use file: URIs to access other files in the same directory or sub-directories if the names are known or guessed. The Fetch API can then be used to read the contents of any files stored in these directories and they may uploaded to a server. It was demonstrated that in combination with a popular Android messaging app, if a malicious HTML attachment is sent to a user and they opened that attachment in Firefox, due to that app's predictable pattern for locally-saved file names, it is possible to read attachments the victim received from other correspondents. This vulnerability affects Firefox ESR < 60.8, Firefox < 68, and Thunderbird < 60.8. | CVSS3: 6.5 | 20% Средний | больше 6 лет назад | |
CVE-2019-11730 A vulnerability exists where if a user opens a locally saved HTML file ... | CVSS3: 6.5 | 20% Средний | больше 6 лет назад | |
GHSA-353x-8rf5-m26c A vulnerability exists where if a user opens a locally saved HTML file, this file can use file: URIs to access other files in the same directory or sub-directories if the names are known or guessed. The Fetch API can then be used to read the contents of any files stored in these directories and they may uploaded to a server. It was demonstrated that in combination with a popular Android messaging app, if a malicious HTML attachment is sent to a user and they opened that attachment in Firefox, due to that app's predictable pattern for locally-saved file names, it is possible to read attachments the victim received from other correspondents. This vulnerability affects Firefox ESR < 60.8, Firefox < 68, and Thunderbird < 60.8. | CVSS3: 6.5 | 20% Средний | больше 3 лет назад | |
ELSA-2019-1799 ELSA-2019-1799: thunderbird security and bug fix update (IMPORTANT) | больше 6 лет назад | |||
ELSA-2019-1777 ELSA-2019-1777: thunderbird security update (IMPORTANT) | больше 6 лет назад | |||
ELSA-2019-1775 ELSA-2019-1775: thunderbird security update (IMPORTANT) | больше 6 лет назад | |||
ELSA-2019-1765 ELSA-2019-1765: firefox security update (CRITICAL) | больше 6 лет назад | |||
ELSA-2019-1764 ELSA-2019-1764: firefox security update (CRITICAL) | больше 6 лет назад | |||
ELSA-2019-1763 ELSA-2019-1763: firefox security update (CRITICAL) | больше 6 лет назад | |||
openSUSE-SU-2019:1813-1 Security update for MozillaThunderbird | больше 6 лет назад | |||
openSUSE-SU-2019:1811-1 Security update for MozillaFirefox | больше 6 лет назад | |||
openSUSE-SU-2019:1782-1 Security update for MozillaFirefox | больше 6 лет назад | |||
SUSE-SU-2019:1960-1 Security update for MozillaThunderbird | больше 6 лет назад | |||
SUSE-SU-2019:1869-1 Security update for MozillaFirefox | больше 6 лет назад | |||
SUSE-SU-2019:1861-1 Security update for MozillaFirefox | больше 6 лет назад | |||
SUSE-SU-2019:14124-1 Security update for MozillaFirefox | больше 6 лет назад | |||
openSUSE-SU-2019:2249-1 Security update for MozillaThunderbird | больше 6 лет назад |
Уязвимостей на страницу