Логотип exploitDog
bind:"BDU:2022-04382" OR bind:"CVE-2022-31742"
Консоль
Логотип exploitDog

exploitDog

bind:"BDU:2022-04382" OR bind:"CVE-2022-31742"

Количество 18

Количество 18

fstec логотип

BDU:2022-04382

около 3 лет назад

Уязвимость реализации механизма CORS (Cross-Origin Resource Sharing) браузеров Firefox, Firefox ESR и почтового клиента Thunderbird, позволяющая нарушителю обойти ограничения безопасности и получить несанкционированный доступ к защищаемой информации

CVSS3: 6.1
EPSS: Низкий
ubuntu логотип

CVE-2022-31742

больше 2 лет назад

An attacker could have exploited a timing attack by sending a large number of allowCredential entries and detecting the difference between invalid key handles and cross-origin key handles. This could have led to cross-origin account linking in violation of WebAuthn goals. This vulnerability affects Thunderbird < 91.10, Firefox < 101, and Firefox ESR < 91.10.

CVSS3: 6.5
EPSS: Низкий
redhat логотип

CVE-2022-31742

около 3 лет назад

An attacker could have exploited a timing attack by sending a large number of allowCredential entries and detecting the difference between invalid key handles and cross-origin key handles. This could have led to cross-origin account linking in violation of WebAuthn goals. This vulnerability affects Thunderbird < 91.10, Firefox < 101, and Firefox ESR < 91.10.

CVSS3: 6.1
EPSS: Низкий
nvd логотип

CVE-2022-31742

больше 2 лет назад

An attacker could have exploited a timing attack by sending a large number of allowCredential entries and detecting the difference between invalid key handles and cross-origin key handles. This could have led to cross-origin account linking in violation of WebAuthn goals. This vulnerability affects Thunderbird < 91.10, Firefox < 101, and Firefox ESR < 91.10.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2022-31742

больше 2 лет назад

An attacker could have exploited a timing attack by sending a large nu ...

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-5frx-2qvr-6r92

больше 2 лет назад

An attacker could have exploited a timing attack by sending a large number of allowCredential entries and detecting the difference between invalid key handles and cross-origin key handles. This could have led to cross-origin account linking in violation of WebAuthn goals. This vulnerability affects Thunderbird < 91.10, Firefox < 101, and Firefox ESR < 91.10.

CVSS3: 6.5
EPSS: Низкий
rocky логотип

RLSA-2022:4872

около 3 лет назад

Important: firefox security update

EPSS: Низкий
oracle-oval логотип

ELSA-2022-4873

около 3 лет назад

ELSA-2022-4873: firefox security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2022-4872

около 3 лет назад

ELSA-2022-4872: firefox security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2022-4870

около 3 лет назад

ELSA-2022-4870: firefox security update (IMPORTANT)

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2022:1927-1

около 3 лет назад

Security update for MozillaFirefox

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2022:1921-1

около 3 лет назад

Security update for MozillaFirefox

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2022:1920-1

около 3 лет назад

Security update for MozillaFirefox

EPSS: Низкий
rocky логотип

RLSA-2022:4887

около 3 лет назад

Important: thunderbird security update

EPSS: Низкий
oracle-oval логотип

ELSA-2022-4892

около 3 лет назад

ELSA-2022-4892: thunderbird security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2022-4891

около 3 лет назад

ELSA-2022-4891: thunderbird security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2022-4887

около 3 лет назад

ELSA-2022-4887: thunderbird security update (IMPORTANT)

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2022:2062-1

около 3 лет назад

Security update for MozillaThunderbird

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
fstec логотип
BDU:2022-04382

Уязвимость реализации механизма CORS (Cross-Origin Resource Sharing) браузеров Firefox, Firefox ESR и почтового клиента Thunderbird, позволяющая нарушителю обойти ограничения безопасности и получить несанкционированный доступ к защищаемой информации

CVSS3: 6.1
0%
Низкий
около 3 лет назад
ubuntu логотип
CVE-2022-31742

An attacker could have exploited a timing attack by sending a large number of allowCredential entries and detecting the difference between invalid key handles and cross-origin key handles. This could have led to cross-origin account linking in violation of WebAuthn goals. This vulnerability affects Thunderbird < 91.10, Firefox < 101, and Firefox ESR < 91.10.

CVSS3: 6.5
0%
Низкий
больше 2 лет назад
redhat логотип
CVE-2022-31742

An attacker could have exploited a timing attack by sending a large number of allowCredential entries and detecting the difference between invalid key handles and cross-origin key handles. This could have led to cross-origin account linking in violation of WebAuthn goals. This vulnerability affects Thunderbird < 91.10, Firefox < 101, and Firefox ESR < 91.10.

CVSS3: 6.1
0%
Низкий
около 3 лет назад
nvd логотип
CVE-2022-31742

An attacker could have exploited a timing attack by sending a large number of allowCredential entries and detecting the difference between invalid key handles and cross-origin key handles. This could have led to cross-origin account linking in violation of WebAuthn goals. This vulnerability affects Thunderbird < 91.10, Firefox < 101, and Firefox ESR < 91.10.

CVSS3: 6.5
0%
Низкий
больше 2 лет назад
debian логотип
CVE-2022-31742

An attacker could have exploited a timing attack by sending a large nu ...

CVSS3: 6.5
0%
Низкий
больше 2 лет назад
github логотип
GHSA-5frx-2qvr-6r92

An attacker could have exploited a timing attack by sending a large number of allowCredential entries and detecting the difference between invalid key handles and cross-origin key handles. This could have led to cross-origin account linking in violation of WebAuthn goals. This vulnerability affects Thunderbird < 91.10, Firefox < 101, and Firefox ESR < 91.10.

CVSS3: 6.5
0%
Низкий
больше 2 лет назад
rocky логотип
RLSA-2022:4872

Important: firefox security update

около 3 лет назад
oracle-oval логотип
ELSA-2022-4873

ELSA-2022-4873: firefox security update (IMPORTANT)

около 3 лет назад
oracle-oval логотип
ELSA-2022-4872

ELSA-2022-4872: firefox security update (IMPORTANT)

около 3 лет назад
oracle-oval логотип
ELSA-2022-4870

ELSA-2022-4870: firefox security update (IMPORTANT)

около 3 лет назад
suse-cvrf логотип
SUSE-SU-2022:1927-1

Security update for MozillaFirefox

около 3 лет назад
suse-cvrf логотип
SUSE-SU-2022:1921-1

Security update for MozillaFirefox

около 3 лет назад
suse-cvrf логотип
SUSE-SU-2022:1920-1

Security update for MozillaFirefox

около 3 лет назад
rocky логотип
RLSA-2022:4887

Important: thunderbird security update

около 3 лет назад
oracle-oval логотип
ELSA-2022-4892

ELSA-2022-4892: thunderbird security update (IMPORTANT)

около 3 лет назад
oracle-oval логотип
ELSA-2022-4891

ELSA-2022-4891: thunderbird security update (IMPORTANT)

около 3 лет назад
oracle-oval логотип
ELSA-2022-4887

ELSA-2022-4887: thunderbird security update (IMPORTANT)

около 3 лет назад
suse-cvrf логотип
SUSE-SU-2022:2062-1

Security update for MozillaThunderbird

около 3 лет назад

Уязвимостей на страницу