Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:24442
HistoryApr 10, 2020 - 12:54 a.m.

Arbitrary Code Execution

2020-04-1000:54:15
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
12

EPSS

0.023

Percentile

89.8%

firefox is vulnerable to arbitrary code execution. A flaw was found in the way Firefox sanitized HTML content in extensions. If an extension loaded or rendered malicious content using the ParanoidFragmentSink class, it could fail to safely display the content, causing Firefox to execute arbitrary JavaScript with the privileges of the user running Firefox.