Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:24857
HistoryApr 10, 2020 - 1:07 a.m.

Arbitrary Code Execution

2020-04-1001:07:17
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
12

0.917 High

EPSS

Percentile

98.9%

firefox is vulnerable to arbitrary code execution. The vulnerability exists as a use-after-free flaw was found in the way Firefox removed nsDOMAttribute child nodes. In certain circumstances, due to the premature otification of AttributeChildRemoved, a malicious script could possibly use this flaw to cause Firefox to crash or, potentially, execute arbitrary code with the privileges of the user running Firefox.