Lucene search

K
nessusTenable700323.PRM
HistoryAug 21, 2018 - 12:00 a.m.

Mozilla Firefox < 57.0.1 Multiple Vulnerabilities

2018-08-2100:00:00
Tenable
www.tenable.com
16

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

EPSS

0.004

Percentile

74.0%

Versions of Mozilla Firefox earlier than 57.0.1 are unpatched for the following vulnerabilities :

  • A flaw exists in the ‘PerDocumentStyleDataImpl::visited_styles_enabled()’ function in ‘servo/components/style/gecko/data.rs’. The issue is triggered when handling the CSS ‘:visited’ selector for a document being used as an SVG image. With a specially crafted web page, a context-dependent attacker disclose visited history information. (CVE-2017-7844)
  • A flaw exists in the ‘FactoryOp::CheckPermission()’ function in ‘dom/indexedDB/ActorsParent.cpp’ that is triggered as a web worker in Private Browsing mode can write to IndexedDB. With a specially crafted web page, a context-dependent attacker can uniquely fingerprint a user even when browsing in Private Browsing mode. (CVE-2017-7843)
Binary data 700323.prm

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

EPSS

0.004

Percentile

74.0%