Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Mozilla Firefox before 3.6.7 and Thunderbird before 3.1.1 do not properly implement read restrictions for CANVAS elements, which allows remote attackers to obtain sensitive cross-origin information via vectors involving reference retention and node deletion.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Mozilla Firefox canvas元素跨域信息泄露漏洞
Vulnerability Description
Mozilla Firefox是美国Mozilla基金会开发的一款开源Web浏览器。 攻击者可以利用canvas元素破坏同源策略读取其他站点的数据。尽管对canvas元素设置了读限制,但可通过保持对元素上下文的引用并从DOM删除相关的canvas节点绕过上述限制,获取跨域敏感信息。
CVSS Information
N/A
Vulnerability Type
N/A