Know every vulnerabilitybefore it knows you.
DevGuard continuously monitors your dependencies and alerts you when CVEs like this one affect your stack — with real-time threat intelligence built for developers.
- Feiten
Mozilla heeft kwetsbaarheden verholpen in Firefox en Thunderbird (Specifiek voor versies onder 134 en 128.6).
- Interpretaties
De kwetsbaarheden omvatten onder andere client-side path traversal, privilege escalation en use-after-free condities. Deze kwetsbaarheden kunnen door kwaadwillenden worden misbruikt om ongeautoriseerde toegang te verkrijgen, crashes te veroorzaken of mogelijkerwijze willekeurige code uit te voeren.
- Oplossingen
Mozilla heeft updates uitgebracht om de kwetsbaarheden te verhelpen. Zie bijgevoegde referenties voor meer informatie.
- Kans
medium
- Schade
high
- CWE-441
Unintended Proxy or Intermediary ('Confused Deputy')
- CWE-601
URL Redirection to Untrusted Site ('Open Redirect')
- CWE-288
Authentication Bypass Using an Alternate Path or Channel
- CWE-451
User Interface (UI) Misrepresentation of Critical Information
- CWE-119
Improper Restriction of Operations within the Bounds of a Memory Buffer
- CWE-416
Use After Free
- CWE-295
Improper Certificate Validation
- CWE-863
Incorrect Authorization
- CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
- CWE-787
Out-of-bounds Write
- CWE-120
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
- CWE-20
Improper Input Validation
- CWE-346
Origin Validation Error
- CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Continuously monitor your dependencies and get alerted when vulnerabilities like this one affect your stack.
Checkout DevGuard