Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 24

Количество 24

github логотип

GHSA-353x-8rf5-m26c

около 4 лет назад

A vulnerability exists where if a user opens a locally saved HTML file, this file can use file: URIs to access other files in the same directory or sub-directories if the names are known or guessed. The Fetch API can then be used to read the contents of any files stored in these directories and they may uploaded to a server. It was demonstrated that in combination with a popular Android messaging app, if a malicious HTML attachment is sent to a user and they opened that attachment in Firefox, due to that app's predictable pattern for locally-saved file names, it is possible to read attachments the victim received from other correspondents. This vulnerability affects Firefox ESR < 60.8, Firefox < 68, and Thunderbird < 60.8.

CVSS3: 6.5
EPSS: Средний
ubuntu логотип

CVE-2019-11730

около 7 лет назад

A vulnerability exists where if a user opens a locally saved HTML file, this file can use file: URIs to access other files in the same directory or sub-directories if the names are known or guessed. The Fetch API can then be used to read the contents of any files stored in these directories and they may uploaded to a server. It was demonstrated that in combination with a popular Android messaging app, if a malicious HTML attachment is sent to a user and they opened that attachment in Firefox, due to that app's predictable pattern for locally-saved file names, it is possible to read attachments the victim received from other correspondents. This vulnerability affects Firefox ESR < 60.8, Firefox < 68, and Thunderbird < 60.8.

CVSS3: 6.5
EPSS: Средний
redhat логотип

CVE-2019-11730

около 7 лет назад

A vulnerability exists where if a user opens a locally saved HTML file, this file can use file: URIs to access other files in the same directory or sub-directories if the names are known or guessed. The Fetch API can then be used to read the contents of any files stored in these directories and they may uploaded to a server. It was demonstrated that in combination with a popular Android messaging app, if a malicious HTML attachment is sent to a user and they opened that attachment in Firefox, due to that app's predictable pattern for locally-saved file names, it is possible to read attachments the victim received from other correspondents. This vulnerability affects Firefox ESR < 60.8, Firefox < 68, and Thunderbird < 60.8.

CVSS3: 6.1
EPSS: Средний
nvd логотип

CVE-2019-11730

около 7 лет назад

A vulnerability exists where if a user opens a locally saved HTML file, this file can use file: URIs to access other files in the same directory or sub-directories if the names are known or guessed. The Fetch API can then be used to read the contents of any files stored in these directories and they may uploaded to a server. It was demonstrated that in combination with a popular Android messaging app, if a malicious HTML attachment is sent to a user and they opened that attachment in Firefox, due to that app's predictable pattern for locally-saved file names, it is possible to read attachments the victim received from other correspondents. This vulnerability affects Firefox ESR < 60.8, Firefox < 68, and Thunderbird < 60.8.

CVSS3: 6.5
EPSS: Средний
debian логотип

CVE-2019-11730

около 7 лет назад

A vulnerability exists where if a user opens a locally saved HTML file ...

CVSS3: 6.5
EPSS: Средний
fstec логотип

BDU:2020-00723

около 7 лет назад

Уязвимость веб-браузеров Firefox, Firefox ESR и программы для работы с электронной почтой Thunderbird, связанная с отсутствием защиты служебных данных, позволяющая нарушителю получить несанкционированный доступ к конфиденциальным данным

CVSS3: 6.5
EPSS: Средний
oracle-oval логотип

ELSA-2019-1799

около 7 лет назад

ELSA-2019-1799: thunderbird security and bug fix update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2019-1777

около 7 лет назад

ELSA-2019-1777: thunderbird security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2019-1775

около 7 лет назад

ELSA-2019-1775: thunderbird security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2019-1765

около 7 лет назад

ELSA-2019-1765: firefox security update (CRITICAL)

EPSS: Низкий
oracle-oval логотип

ELSA-2019-1764

около 7 лет назад

ELSA-2019-1764: firefox security update (CRITICAL)

EPSS: Низкий
oracle-oval логотип

ELSA-2019-1763

около 7 лет назад

ELSA-2019-1763: firefox security update (CRITICAL)

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2019:1813-1

около 7 лет назад

Security update for MozillaThunderbird

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2019:1811-1

около 7 лет назад

Security update for MozillaFirefox

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2019:1782-1

около 7 лет назад

Security update for MozillaFirefox

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2019:1960-1

около 7 лет назад

Security update for MozillaThunderbird

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2019:1869-1

около 7 лет назад

Security update for MozillaFirefox

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2019:1861-1

около 7 лет назад

Security update for MozillaFirefox

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2019:14124-1

около 7 лет назад

Security update for MozillaFirefox

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2019:2249-1

почти 7 лет назад

Security update for MozillaThunderbird

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-353x-8rf5-m26c

A vulnerability exists where if a user opens a locally saved HTML file, this file can use file: URIs to access other files in the same directory or sub-directories if the names are known or guessed. The Fetch API can then be used to read the contents of any files stored in these directories and they may uploaded to a server. It was demonstrated that in combination with a popular Android messaging app, if a malicious HTML attachment is sent to a user and they opened that attachment in Firefox, due to that app's predictable pattern for locally-saved file names, it is possible to read attachments the victim received from other correspondents. This vulnerability affects Firefox ESR < 60.8, Firefox < 68, and Thunderbird < 60.8.

CVSS3: 6.5
20%
Средний
около 4 лет назад
ubuntu логотип
CVE-2019-11730

A vulnerability exists where if a user opens a locally saved HTML file, this file can use file: URIs to access other files in the same directory or sub-directories if the names are known or guessed. The Fetch API can then be used to read the contents of any files stored in these directories and they may uploaded to a server. It was demonstrated that in combination with a popular Android messaging app, if a malicious HTML attachment is sent to a user and they opened that attachment in Firefox, due to that app's predictable pattern for locally-saved file names, it is possible to read attachments the victim received from other correspondents. This vulnerability affects Firefox ESR < 60.8, Firefox < 68, and Thunderbird < 60.8.

CVSS3: 6.5
20%
Средний
около 7 лет назад
redhat логотип
CVE-2019-11730

A vulnerability exists where if a user opens a locally saved HTML file, this file can use file: URIs to access other files in the same directory or sub-directories if the names are known or guessed. The Fetch API can then be used to read the contents of any files stored in these directories and they may uploaded to a server. It was demonstrated that in combination with a popular Android messaging app, if a malicious HTML attachment is sent to a user and they opened that attachment in Firefox, due to that app's predictable pattern for locally-saved file names, it is possible to read attachments the victim received from other correspondents. This vulnerability affects Firefox ESR < 60.8, Firefox < 68, and Thunderbird < 60.8.

CVSS3: 6.1
20%
Средний
около 7 лет назад
nvd логотип
CVE-2019-11730

A vulnerability exists where if a user opens a locally saved HTML file, this file can use file: URIs to access other files in the same directory or sub-directories if the names are known or guessed. The Fetch API can then be used to read the contents of any files stored in these directories and they may uploaded to a server. It was demonstrated that in combination with a popular Android messaging app, if a malicious HTML attachment is sent to a user and they opened that attachment in Firefox, due to that app's predictable pattern for locally-saved file names, it is possible to read attachments the victim received from other correspondents. This vulnerability affects Firefox ESR < 60.8, Firefox < 68, and Thunderbird < 60.8.

CVSS3: 6.5
20%
Средний
около 7 лет назад
debian логотип
CVE-2019-11730

A vulnerability exists where if a user opens a locally saved HTML file ...

CVSS3: 6.5
20%
Средний
около 7 лет назад
fstec логотип
BDU:2020-00723

Уязвимость веб-браузеров Firefox, Firefox ESR и программы для работы с электронной почтой Thunderbird, связанная с отсутствием защиты служебных данных, позволяющая нарушителю получить несанкционированный доступ к конфиденциальным данным

CVSS3: 6.5
20%
Средний
около 7 лет назад
oracle-oval логотип
ELSA-2019-1799

ELSA-2019-1799: thunderbird security and bug fix update (IMPORTANT)

около 7 лет назад
oracle-oval логотип
ELSA-2019-1777

ELSA-2019-1777: thunderbird security update (IMPORTANT)

около 7 лет назад
oracle-oval логотип
ELSA-2019-1775

ELSA-2019-1775: thunderbird security update (IMPORTANT)

около 7 лет назад
oracle-oval логотип
ELSA-2019-1765

ELSA-2019-1765: firefox security update (CRITICAL)

около 7 лет назад
oracle-oval логотип
ELSA-2019-1764

ELSA-2019-1764: firefox security update (CRITICAL)

около 7 лет назад
oracle-oval логотип
ELSA-2019-1763

ELSA-2019-1763: firefox security update (CRITICAL)

около 7 лет назад
suse-cvrf логотип
openSUSE-SU-2019:1813-1

Security update for MozillaThunderbird

около 7 лет назад
suse-cvrf логотип
openSUSE-SU-2019:1811-1

Security update for MozillaFirefox

около 7 лет назад
suse-cvrf логотип
openSUSE-SU-2019:1782-1

Security update for MozillaFirefox

около 7 лет назад
suse-cvrf логотип
SUSE-SU-2019:1960-1

Security update for MozillaThunderbird

около 7 лет назад
suse-cvrf логотип
SUSE-SU-2019:1869-1

Security update for MozillaFirefox

около 7 лет назад
suse-cvrf логотип
SUSE-SU-2019:1861-1

Security update for MozillaFirefox

около 7 лет назад
suse-cvrf логотип
SUSE-SU-2019:14124-1

Security update for MozillaFirefox

около 7 лет назад
suse-cvrf логотип
openSUSE-SU-2019:2249-1

Security update for MozillaThunderbird

почти 7 лет назад

Уязвимостей на страницу