7.5
CVE-2017-7843
- EPSS 2.95%
- Veröffentlicht 11.06.2018 21:29:11
- Zuletzt bearbeitet 25.11.2025 17:50:16
- Erkennungen
When Private Browsing mode is used, it is possible for a web worker to write persistent data to IndexedDB and fingerprint a user uniquely. IndexedDB should not be available in Private Browsing mode and this stored data will persist across multiple private browsing mode sessions because it is not cleared when exiting. This vulnerability affects Firefox ESR < 52.5.2 and Firefox < 57.0.1.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Debian ≫ Debian Linux Version 7.0
Debian ≫ Debian Linux Version 8.0
Debian ≫ Debian Linux Version 9.0
Redhat ≫ Enterprise Linux Desktop Version 6.0
Redhat ≫ Enterprise Linux Desktop Version 7.0
Redhat ≫ Enterprise Linux Server Version 6.0
Redhat ≫ Enterprise Linux Server Version 7.0
Redhat ≫ Enterprise Linux Server Aus Version 7.4
Redhat ≫ Enterprise Linux Server Eus Version 7.4
Redhat ≫ Enterprise Linux Server Eus Version 7.5
Redhat ≫ Enterprise Linux Workstation Version 6.0
Redhat ≫ Enterprise Linux Workstation Version 7.0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 2.95% | 0.86 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 7.5 | 3.9 | 3.6 |
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
|
| NIST | 5 | 10 | 2.9 |
AV:N/AC:L/Au:N/C:P/I:N/A:N
|
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
http://www.securityfocus.com/bid/102039
http://www.securityfocus.com/bid/102112
http://www.securitytracker.com/id/1039954
https://access.redhat.com/errata/RHSA-2017:3382
https://bugzilla.mozilla.org/show_bug.cgi?id=1410106
https://lists.debian.org/debian-lts-announce/2017/12/msg00003.html
https://www.debian.org/security/2017/dsa-4062
https://www.mozilla.org/security/advisories/mfsa2017-27/
https://www.mozilla.org/security/advisories/mfsa2017-28/