Lucene search

K
mozillaMozilla FoundationMFSA2010-47
HistoryJul 20, 2010 - 12:00 a.m.

Cross-origin data leakage from script filename in error messages β€” Mozilla

2010-07-2000:00:00
Mozilla Foundation
www.mozilla.org
23

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

EPSS

0.003

Percentile

68.4%

Security researcher Soroush Dalili reported that potentially sensitive URL parameters could be leaked across domains upon script errors when the script filename and line number is included in the error message.

Affected configurations

Vulners
Node
mozillafirefoxRange<3.5.11
OR
mozillafirefoxRange<3.6.7
OR
mozillaseamonkeyRange<2.0.6
OR
mozillathunderbirdRange<3.0.6
OR
mozillathunderbirdRange<3.1.1
VendorProductVersionCPE
mozillafirefox*cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*
mozillaseamonkey*cpe:2.3:a:mozilla:seamonkey:*:*:*:*:*:*:*:*
mozillathunderbird*cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

EPSS

0.003

Percentile

68.4%