Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The importScripts function in the Web Workers API implementation in Mozilla Firefox before 43.0 allows remote attackers to bypass the Same Origin Policy by triggering use of the no-cors mode in the fetch API to attempt resource access that throws an exception, leading to information disclosure after a rethrow.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Mozilla Firefox Web Workers API实现信息泄露漏洞
Vulnerability Description
Mozilla Firefox是美国Mozilla基金会开发的一款开源Web浏览器。 Mozilla Firefox 42.0及之前版本的Web Workers API实现过程中的‘importScripts’函数存在安全漏洞。远程攻击者可借助error事件利用该漏洞绕过同源策略,获取敏感信息。
CVSS Information
N/A
Vulnerability Type
N/A