Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2012-0958

Опубликовано: 26 дек. 2012
Источник: nvd
CVSS2: 4.3
EPSS Низкий

Описание

content/unity-api.js in the unity-firefox-extension extension 2.4.1 for Firefox exposes the toDataURL function in an API call, which allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via a crafted webpage.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:ps_project_management_team:unity-firefox-extension:2.4.1:-:*:*:*:firefox:*:*

EPSS

Процентиль: 55%
0.00319
Низкий

4.3 Medium

CVSS2

Дефекты

NVD-CWE-Other

Связанные уязвимости

ubuntu
около 13 лет назад

content/unity-api.js in the unity-firefox-extension extension 2.4.1 for Firefox exposes the toDataURL function in an API call, which allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via a crafted webpage.

github
больше 3 лет назад

content/unity-api.js in the unity-firefox-extension extension 2.4.1 for Firefox exposes the toDataURL function in an API call, which allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via a crafted webpage.

EPSS

Процентиль: 55%
0.00319
Низкий

4.3 Medium

CVSS2

Дефекты

NVD-CWE-Other