CVE

Id
102748  
CVE No.
CVE-2017-5928  
Status
Candidate  
Description
The W3C High Resolution Time API, as implemented in various web browsers, does not consider that memory-reference times can be measured by a performance.now "Time to Tick" approach even with the https://bugzilla.mozilla.org/show_bug.cgi?id=1167489#c9 protection mechanism in place, which makes it easier for remote attackers to conduct AnC attacks via crafted JavaScript code.  
Phase
Assigned (20170207)  
Votes
None (candidate not yet proposed)  
Comments