Lucene search

K
redosRedosROS-20221229-02
HistoryDec 29, 2022 - 12:00 a.m.

ROS-20221229-02

2022-12-2900:00:00
redos.red-soft.ru
14
mozilla firefox
vulnerability
remote attacker
arbitrary files
clipboard
ipc messages

CVSS3

8.6

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N

EPSS

0.002

Percentile

61.2%

A vulnerability in the Mozilla Firefox browser is related to the fact that a process can partially exit the sandbox and
read arbitrary files using IPC messages associated with the clipboard. Exploitation of the
of the vulnerability could allow an attacker acting remotely to open a given source and read the
potentially sensitive data

OSVersionArchitecturePackageVersionFilename
redos7.3x86_64firefox< 102.6.0-1UNKNOWN

CVSS3

8.6

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N

EPSS

0.002

Percentile

61.2%