Логотип exploitDog
bind:"GHSA-jhx9-2v44-3f39" OR bind:"CVE-2016-9902"
Консоль
Логотип exploitDog

exploitDog

bind:"GHSA-jhx9-2v44-3f39" OR bind:"CVE-2016-9902"

Количество 11

Количество 11

github логотип

GHSA-jhx9-2v44-3f39

больше 3 лет назад

The Pocket toolbar button, once activated, listens for events fired from it's own pages but does not verify the origin of incoming events. This allows content from other origins to fire events and inject content and commands into the Pocket context. Note: this issue does not affect users with e10s enabled. This vulnerability affects Firefox ESR < 45.6 and Firefox < 50.1.

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2016-9902

около 7 лет назад

The Pocket toolbar button, once activated, listens for events fired from it's own pages but does not verify the origin of incoming events. This allows content from other origins to fire events and inject content and commands into the Pocket context. Note: this issue does not affect users with e10s enabled. This vulnerability affects Firefox ESR < 45.6 and Firefox < 50.1.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2016-9902

больше 8 лет назад

The Pocket toolbar button, once activated, listens for events fired from it's own pages but does not verify the origin of incoming events. This allows content from other origins to fire events and inject content and commands into the Pocket context. Note: this issue does not affect users with e10s enabled. This vulnerability affects Firefox ESR < 45.6 and Firefox < 50.1.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2016-9902

около 7 лет назад

The Pocket toolbar button, once activated, listens for events fired from it's own pages but does not verify the origin of incoming events. This allows content from other origins to fire events and inject content and commands into the Pocket context. Note: this issue does not affect users with e10s enabled. This vulnerability affects Firefox ESR < 45.6 and Firefox < 50.1.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2016-9902

около 7 лет назад

The Pocket toolbar button, once activated, listens for events fired fr ...

CVSS3: 7.5
EPSS: Низкий
oracle-oval логотип

ELSA-2016-2973

больше 8 лет назад

ELSA-2016-2973: thunderbird security update (IMPORTANT)

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2016:3223-1

больше 8 лет назад

Security update for MozillaFirefox

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2016:3222-1

больше 8 лет назад

Security update for MozillaFirefox

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2016:3210-1

больше 8 лет назад

Security update for MozillaFirefox

EPSS: Низкий
oracle-oval логотип

ELSA-2016-2946

больше 8 лет назад

ELSA-2016-2946: firefox security update (CRITICAL)

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2016:3184-1

больше 8 лет назад

Security update for MozillaFirefox

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-jhx9-2v44-3f39

The Pocket toolbar button, once activated, listens for events fired from it's own pages but does not verify the origin of incoming events. This allows content from other origins to fire events and inject content and commands into the Pocket context. Note: this issue does not affect users with e10s enabled. This vulnerability affects Firefox ESR < 45.6 and Firefox < 50.1.

CVSS3: 7.5
0%
Низкий
больше 3 лет назад
ubuntu логотип
CVE-2016-9902

The Pocket toolbar button, once activated, listens for events fired from it's own pages but does not verify the origin of incoming events. This allows content from other origins to fire events and inject content and commands into the Pocket context. Note: this issue does not affect users with e10s enabled. This vulnerability affects Firefox ESR < 45.6 and Firefox < 50.1.

CVSS3: 7.5
0%
Низкий
около 7 лет назад
redhat логотип
CVE-2016-9902

The Pocket toolbar button, once activated, listens for events fired from it's own pages but does not verify the origin of incoming events. This allows content from other origins to fire events and inject content and commands into the Pocket context. Note: this issue does not affect users with e10s enabled. This vulnerability affects Firefox ESR < 45.6 and Firefox < 50.1.

CVSS3: 7.5
0%
Низкий
больше 8 лет назад
nvd логотип
CVE-2016-9902

The Pocket toolbar button, once activated, listens for events fired from it's own pages but does not verify the origin of incoming events. This allows content from other origins to fire events and inject content and commands into the Pocket context. Note: this issue does not affect users with e10s enabled. This vulnerability affects Firefox ESR < 45.6 and Firefox < 50.1.

CVSS3: 7.5
0%
Низкий
около 7 лет назад
debian логотип
CVE-2016-9902

The Pocket toolbar button, once activated, listens for events fired fr ...

CVSS3: 7.5
0%
Низкий
около 7 лет назад
oracle-oval логотип
ELSA-2016-2973

ELSA-2016-2973: thunderbird security update (IMPORTANT)

больше 8 лет назад
suse-cvrf логотип
SUSE-SU-2016:3223-1

Security update for MozillaFirefox

больше 8 лет назад
suse-cvrf логотип
SUSE-SU-2016:3222-1

Security update for MozillaFirefox

больше 8 лет назад
suse-cvrf логотип
SUSE-SU-2016:3210-1

Security update for MozillaFirefox

больше 8 лет назад
oracle-oval логотип
ELSA-2016-2946

ELSA-2016-2946: firefox security update (CRITICAL)

больше 8 лет назад
suse-cvrf логотип
openSUSE-SU-2016:3184-1

Security update for MozillaFirefox

больше 8 лет назад

Уязвимостей на страницу