Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 18

Количество 18

github логотип

GHSA-wgfq-5c99-wv2w

около 4 лет назад

When pasting a &lt;style&gt; tag from the clipboard into a rich text editor, the CSS sanitizer does not escape &lt; and &gt; characters. Because the resulting string is pasted directly into the text node of the element this does not result in a direct injection into the webpage; however, if a webpage subsequently copies the node's innerHTML, assigning it to another innerHTML, this would result in an XSS vulnerability. Two WYSIWYG editors were identified with this behavior, more may exist. This vulnerability affects Firefox ESR < 68.4 and Firefox < 72.

EPSS: Низкий
ubuntu логотип

CVE-2019-17022

больше 6 лет назад

When pasting a &lt;style&gt; tag from the clipboard into a rich text editor, the CSS sanitizer does not escape &lt; and &gt; characters. Because the resulting string is pasted directly into the text node of the element this does not result in a direct injection into the webpage; however, if a webpage subsequently copies the node's innerHTML, assigning it to another innerHTML, this would result in an XSS vulnerability. Two WYSIWYG editors were identified with this behavior, more may exist. This vulnerability affects Firefox ESR < 68.4 and Firefox < 72.

CVSS3: 6.1
EPSS: Низкий
redhat логотип

CVE-2019-17022

больше 6 лет назад

When pasting a &lt;style&gt; tag from the clipboard into a rich text editor, the CSS sanitizer does not escape &lt; and &gt; characters. Because the resulting string is pasted directly into the text node of the element this does not result in a direct injection into the webpage; however, if a webpage subsequently copies the node's innerHTML, assigning it to another innerHTML, this would result in an XSS vulnerability. Two WYSIWYG editors were identified with this behavior, more may exist. This vulnerability affects Firefox ESR < 68.4 and Firefox < 72.

CVSS3: 6.1
EPSS: Низкий
nvd логотип

CVE-2019-17022

больше 6 лет назад

When pasting a &lt;style&gt; tag from the clipboard into a rich text editor, the CSS sanitizer does not escape &lt; and &gt; characters. Because the resulting string is pasted directly into the text node of the element this does not result in a direct injection into the webpage; however, if a webpage subsequently copies the node's innerHTML, assigning it to another innerHTML, this would result in an XSS vulnerability. Two WYSIWYG editors were identified with this behavior, more may exist. This vulnerability affects Firefox ESR < 68.4 and Firefox < 72.

CVSS3: 6.1
EPSS: Низкий
debian логотип

CVE-2019-17022

больше 6 лет назад

When pasting a &lt;style&gt; tag from the clipboard into a rich text e ...

CVSS3: 6.1
EPSS: Низкий
fstec логотип

BDU:2020-01455

больше 6 лет назад

Уязвимость браузеров Firefox, Firefox ESR, связанная с непринятием мер по защите структуры веб-страницы, позволяющая нарушителю оказать воздействие на целостность данных

CVSS3: 6.1
EPSS: Низкий
oracle-oval логотип

ELSA-2020-0127

больше 6 лет назад

ELSA-2020-0127: thunderbird security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2020-0123

около 6 лет назад

ELSA-2020-0123: thunderbird security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2020-0120

больше 6 лет назад

ELSA-2020-0120: thunderbird security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2020-0111

больше 6 лет назад

ELSA-2020-0111: firefox security update (CRITICAL)

EPSS: Низкий
oracle-oval логотип

ELSA-2020-0086

около 6 лет назад

ELSA-2020-0086: firefox security update (CRITICAL)

EPSS: Низкий
oracle-oval логотип

ELSA-2020-0085

больше 6 лет назад

ELSA-2020-0085: firefox security update (CRITICAL)

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2020:0094-1

больше 6 лет назад

Security update for MozillaThunderbird

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2020:0060-1

больше 6 лет назад

Security update for MozillaFirefox

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2020:14268-1

больше 6 лет назад

Security update for MozillaFirefox

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2020:0142-1

больше 6 лет назад

Security update for MozillaThunderbird

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2020:0078-1

больше 6 лет назад

Security update for MozillaFirefox

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2020:0068-1

больше 6 лет назад

Security update for MozillaFirefox

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-wgfq-5c99-wv2w

When pasting a &lt;style&gt; tag from the clipboard into a rich text editor, the CSS sanitizer does not escape &lt; and &gt; characters. Because the resulting string is pasted directly into the text node of the element this does not result in a direct injection into the webpage; however, if a webpage subsequently copies the node's innerHTML, assigning it to another innerHTML, this would result in an XSS vulnerability. Two WYSIWYG editors were identified with this behavior, more may exist. This vulnerability affects Firefox ESR < 68.4 and Firefox < 72.

2%
Низкий
около 4 лет назад
ubuntu логотип
CVE-2019-17022

When pasting a &lt;style&gt; tag from the clipboard into a rich text editor, the CSS sanitizer does not escape &lt; and &gt; characters. Because the resulting string is pasted directly into the text node of the element this does not result in a direct injection into the webpage; however, if a webpage subsequently copies the node's innerHTML, assigning it to another innerHTML, this would result in an XSS vulnerability. Two WYSIWYG editors were identified with this behavior, more may exist. This vulnerability affects Firefox ESR < 68.4 and Firefox < 72.

CVSS3: 6.1
2%
Низкий
больше 6 лет назад
redhat логотип
CVE-2019-17022

When pasting a &lt;style&gt; tag from the clipboard into a rich text editor, the CSS sanitizer does not escape &lt; and &gt; characters. Because the resulting string is pasted directly into the text node of the element this does not result in a direct injection into the webpage; however, if a webpage subsequently copies the node's innerHTML, assigning it to another innerHTML, this would result in an XSS vulnerability. Two WYSIWYG editors were identified with this behavior, more may exist. This vulnerability affects Firefox ESR < 68.4 and Firefox < 72.

CVSS3: 6.1
2%
Низкий
больше 6 лет назад
nvd логотип
CVE-2019-17022

When pasting a &lt;style&gt; tag from the clipboard into a rich text editor, the CSS sanitizer does not escape &lt; and &gt; characters. Because the resulting string is pasted directly into the text node of the element this does not result in a direct injection into the webpage; however, if a webpage subsequently copies the node's innerHTML, assigning it to another innerHTML, this would result in an XSS vulnerability. Two WYSIWYG editors were identified with this behavior, more may exist. This vulnerability affects Firefox ESR < 68.4 and Firefox < 72.

CVSS3: 6.1
2%
Низкий
больше 6 лет назад
debian логотип
CVE-2019-17022

When pasting a &lt;style&gt; tag from the clipboard into a rich text e ...

CVSS3: 6.1
2%
Низкий
больше 6 лет назад
fstec логотип
BDU:2020-01455

Уязвимость браузеров Firefox, Firefox ESR, связанная с непринятием мер по защите структуры веб-страницы, позволяющая нарушителю оказать воздействие на целостность данных

CVSS3: 6.1
2%
Низкий
больше 6 лет назад
oracle-oval логотип
ELSA-2020-0127

ELSA-2020-0127: thunderbird security update (IMPORTANT)

больше 6 лет назад
oracle-oval логотип
ELSA-2020-0123

ELSA-2020-0123: thunderbird security update (IMPORTANT)

около 6 лет назад
oracle-oval логотип
ELSA-2020-0120

ELSA-2020-0120: thunderbird security update (IMPORTANT)

больше 6 лет назад
oracle-oval логотип
ELSA-2020-0111

ELSA-2020-0111: firefox security update (CRITICAL)

больше 6 лет назад
oracle-oval логотип
ELSA-2020-0086

ELSA-2020-0086: firefox security update (CRITICAL)

около 6 лет назад
oracle-oval логотип
ELSA-2020-0085

ELSA-2020-0085: firefox security update (CRITICAL)

больше 6 лет назад
suse-cvrf логотип
openSUSE-SU-2020:0094-1

Security update for MozillaThunderbird

больше 6 лет назад
suse-cvrf логотип
openSUSE-SU-2020:0060-1

Security update for MozillaFirefox

больше 6 лет назад
suse-cvrf логотип
SUSE-SU-2020:14268-1

Security update for MozillaFirefox

больше 6 лет назад
suse-cvrf логотип
SUSE-SU-2020:0142-1

Security update for MozillaThunderbird

больше 6 лет назад
suse-cvrf логотип
SUSE-SU-2020:0078-1

Security update for MozillaFirefox

больше 6 лет назад
suse-cvrf логотип
SUSE-SU-2020:0068-1

Security update for MozillaFirefox

больше 6 лет назад

Уязвимостей на страницу