We found results for “”
CVE-2024-4769
Date: May 14, 2024
When importing resources using Web Workers, error messages would distinguish the difference between "application/javascript" responses and non-script responses. This could have been abused to learn information cross-origin. This vulnerability affects Firefox < 126, Firefox ESR < 115.11, and Thunderbird < 115.11.
Language: C++
Severity Score
Related Resources (9)
Severity Score
Weakness Type (CWE)
Insufficient Type Distinction
CWE-351CVSS v3.1
| Base Score: |
|
|---|---|
| Attack Vector (AV): | NETWORK |
| Attack Complexity (AC): | HIGH |
| Privileges Required (PR): | NONE |
| User Interaction (UI): | NONE |
| Scope (S): | UNCHANGED |
| Confidentiality (C): | HIGH |
| Integrity (I): | NONE |
| Availability (A): | NONE |
Vulnerabilities
Projects
Contact Us


