Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2010-2769

Опубликовано: 07 сент. 2010
Источник: redhat
CVSS2: 5.1
EPSS Низкий

Описание

Cross-site scripting (XSS) vulnerability in Mozilla Firefox before 3.5.12 and 3.6.x before 3.6.9, Thunderbird before 3.0.7 and 3.1.x before 3.1.3, and SeaMonkey before 2.0.7 allows user-assisted remote attackers to inject arbitrary web script or HTML via a selection that is added to a document in which the designMode property is enabled.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6firefoxAffected
Red Hat Enterprise Linux 4firefoxFixedRHSA-2010:068108.09.2010
Red Hat Enterprise Linux 4nsprFixedRHSA-2010:068108.09.2010
Red Hat Enterprise Linux 4nssFixedRHSA-2010:068108.09.2010
Red Hat Enterprise Linux 5firefoxFixedRHSA-2010:068108.09.2010
Red Hat Enterprise Linux 5nsprFixedRHSA-2010:068108.09.2010
Red Hat Enterprise Linux 5nssFixedRHSA-2010:068108.09.2010
Red Hat Enterprise Linux 5xulrunnerFixedRHSA-2010:068108.09.2010

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-79
https://bugzilla.redhat.com/show_bug.cgi?id=630075Mozilla Copy-and-paste or drag-and-drop into designMode document allows XSS (MFSA 2010-62)

EPSS

Процентиль: 79%
0.0207
Низкий

5.1 Medium

CVSS2

Связанные уязвимости

ubuntu
почти 16 лет назад

Cross-site scripting (XSS) vulnerability in Mozilla Firefox before 3.5.12 and 3.6.x before 3.6.9, Thunderbird before 3.0.7 and 3.1.x before 3.1.3, and SeaMonkey before 2.0.7 allows user-assisted remote attackers to inject arbitrary web script or HTML via a selection that is added to a document in which the designMode property is enabled.

nvd
почти 16 лет назад

Cross-site scripting (XSS) vulnerability in Mozilla Firefox before 3.5.12 and 3.6.x before 3.6.9, Thunderbird before 3.0.7 and 3.1.x before 3.1.3, and SeaMonkey before 2.0.7 allows user-assisted remote attackers to inject arbitrary web script or HTML via a selection that is added to a document in which the designMode property is enabled.

debian
почти 16 лет назад

Cross-site scripting (XSS) vulnerability in Mozilla Firefox before 3.5 ...

github
около 4 лет назад

Cross-site scripting (XSS) vulnerability in Mozilla Firefox before 3.5.12 and 3.6.x before 3.6.9, Thunderbird before 3.0.7 and 3.1.x before 3.1.3, and SeaMonkey before 2.0.7 allows user-assisted remote attackers to inject arbitrary web script or HTML via a selection that is added to a document in which the designMode property is enabled.

oracle-oval
почти 16 лет назад

ELSA-2010-0681: firefox security update (CRITICAL)

EPSS

Процентиль: 79%
0.0207
Низкий

5.1 Medium

CVSS2