Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2012-0960

Опубликовано: 24 нояб. 2012
Источник: nvd
CVSS2: 7.5
EPSS Низкий

Описание

Unity integration extension (unity-firefox-extension) before 2.4.1 for Firefox does not properly handle callbacks, which allows remote attackers to cause a denial of service (Firefox crash) and possibly execute arbitrary code via a crafted request.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:ps_project_management_team:unity-firefox-extension:*:-:*:*:*:firefox:*:*
Версия до 2.4.0 (включая)
cpe:2.3:a:ps_project_management_team:unity-firefox-extension:0.02:-:*:*:*:firefox:*:*
cpe:2.3:a:ps_project_management_team:unity-firefox-extension:0.2.1:-:*:*:*:firefox:*:*
cpe:2.3:a:ps_project_management_team:unity-firefox-extension:0.3:-:*:*:*:firefox:*:*
cpe:2.3:a:ps_project_management_team:unity-firefox-extension:0.3.1:-:*:*:*:firefox:*:*
cpe:2.3:a:ps_project_management_team:unity-firefox-extension:2.1:-:*:*:*:firefox:*:*
cpe:2.3:a:ps_project_management_team:unity-firefox-extension:2.2:-:*:*:*:firefox:*:*
cpe:2.3:a:ps_project_management_team:unity-firefox-extension:2.3:-:*:*:*:firefox:*:*
cpe:2.3:a:ps_project_management_team:unity-firefox-extension:2.3.1:-:*:*:*:firefox:*:*
cpe:2.3:a:ps_project_management_team:unity-firefox-extension:2.3.2:-:*:*:*:firefox:*:*
cpe:2.3:a:ps_project_management_team:unity-firefox-extension:2.3.3:-:*:*:*:firefox:*:*
cpe:2.3:a:ps_project_management_team:unity-firefox-extension:2.3.4:-:*:*:*:firefox:*:*
cpe:2.3:a:ps_project_management_team:unity-firefox-extension:2.3.5:-:*:*:*:firefox:*:*

EPSS

Процентиль: 84%
0.02313
Низкий

7.5 High

CVSS2

Дефекты

CWE-20

Связанные уязвимости

ubuntu
около 13 лет назад

Unity integration extension (unity-firefox-extension) before 2.4.1 for Firefox does not properly handle callbacks, which allows remote attackers to cause a denial of service (Firefox crash) and possibly execute arbitrary code via a crafted request.

github
больше 3 лет назад

Unity integration extension (unity-firefox-extension) before 2.4.1 for Firefox does not properly handle callbacks, which allows remote attackers to cause a denial of service (Firefox crash) and possibly execute arbitrary code via a crafted request.

EPSS

Процентиль: 84%
0.02313
Низкий

7.5 High

CVSS2

Дефекты

CWE-20