NoScript Classic before 5.1.8.7, as used in Tor Browser 7.x and other products, allows attackers to bypass script blocking via the text/html;/json Content-Type value.
References
Link | Resource |
---|---|
https://www.zdnet.com/article/exploit-vendor-drops-tor-browser-zero-day-on-twitter/ | Third Party Advisory |
https://twitter.com/Zerodium/status/1039127214602641409 | Third Party Advisory |
https://noscript.net/getit#classic | Release Notes |
Information
Published : 2018-09-12 21:29
Updated : 2019-10-02 17:03
NVD link : CVE-2018-16983
Mitre link : CVE-2018-16983
JSON object : View
CWE
Products Affected
torproject
- tor_browser
noscript
- noscript