7.5
CVE-2020-15502
- EPSS 0.56%
- Veröffentlicht 02.07.2020 11:15:10
- Zuletzt bearbeitet 21.11.2024 05:05:39
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
The DuckDuckGo application through 5.58.0 for Android, and through 7.47.1.0 for iOS, sends hostnames of visited web sites within HTTPS .ico requests to servers in the duckduckgo.com domain, which might make visit data available temporarily at a Potentially Unwanted Endpoint. NOTE: the vendor has stated "the favicon service adheres to our strict privacy policy.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Duckduckgo ≫ Duckduckgo SwPlatformandroid Version <= 5.58.0
Duckduckgo ≫ Duckduckgo SwPlatformiphone_os Version <= 7.47.1.0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.56% | 0.674 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
|
| nvd@nist.gov | 5 | 10 | 2.9 |
AV:N/AC:L/Au:N/C:P/I:N/A:N
|
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.