Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:36932
HistorySep 04, 2022 - 11:46 a.m.

Arbitrary Code Execution

2022-09-0411:46:30
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
8
firefox
code execution
vulnerability
memory address
attacker
software

6.5 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N

0.001 Low

EPSS

Percentile

33.0%

firefox is vulnerable to arbitrary code execution. The vulnerability is possible because the value was not written to an invalid memory address which allows an attacker to inject and execute arbitrary commands.

6.5 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N

0.001 Low

EPSS

Percentile

33.0%