vendor:
Epiphany Web Browser
by:
Dhiraj Mishra
5.5
CVSS
MEDIUM
Denial of Service
79
CWE
Product Name: Epiphany Web Browser
Affected Version From: 3.28.1
Affected Version To: 3.28.1
Patch Exists: NO
Related CWE:
CPE: a:gnome:epiphany:3.28.1
Platforms Tested: Ubuntu 18 64bit
2018
Epiphany Web Browser 3.28.1 – Denial of Service (PoC)
The Epiphany Web Browser 3.28.1 is vulnerable to a Denial of Service (DoS) attack. By bookmarking a page with a malicious JavaScript code, an attacker can cause the browser to crash when the bookmark is accessed.
Mitigation:
The vendor has not released a patch for this vulnerability. As a mitigation measure, users are advised to avoid bookmarking pages with malicious JavaScript code.