Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2011-2486

Опубликовано: 25 мар. 2011
Источник: redhat
CVSS2: 2.6
EPSS Низкий

Описание

nspluginwrapper before 1.4.4 does not properly provide access to NPNVprivateModeBool variable settings, which could prevent Firefox plugins from determining if they should run in Private Browsing mode and allow remote attackers to bypass intended access restrictions, as demonstrated using Flash.

Отчет

Red Hat Enterprise Linux 5 is now in Production 3 Phase of the support and maintenance life cycle. This has been rated as having Low security impact and is not currently planned to be addressed in future updates. For additional information, refer to the Red Hat Enterprise Linux Life Cycle: https://access.redhat.com/support/policy/updates/errata/.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5nspluginwrapperWill not fix
Red Hat Enterprise Linux 6nspluginwrapperFixedRHSA-2012:145913.11.2012

Показывать по

Дополнительная информация

Статус:

Low
https://bugzilla.redhat.com/show_bug.cgi?id=715384nspluginwrapper: NPNVprivateModeBool variable not forwarded

EPSS

Процентиль: 75%
0.00919
Низкий

2.6 Low

CVSS2

Связанные уязвимости

ubuntu
почти 13 лет назад

nspluginwrapper before 1.4.4 does not properly provide access to NPNVprivateModeBool variable settings, which could prevent Firefox plugins from determining if they should run in Private Browsing mode and allow remote attackers to bypass intended access restrictions, as demonstrated using Flash.

nvd
почти 13 лет назад

nspluginwrapper before 1.4.4 does not properly provide access to NPNVprivateModeBool variable settings, which could prevent Firefox plugins from determining if they should run in Private Browsing mode and allow remote attackers to bypass intended access restrictions, as demonstrated using Flash.

debian
почти 13 лет назад

nspluginwrapper before 1.4.4 does not properly provide access to NPNVp ...

github
больше 3 лет назад

nspluginwrapper before 1.4.4 does not properly provide access to NPNVprivateModeBool variable settings, which could prevent Firefox plugins from determining if they should run in Private Browsing mode and allow remote attackers to bypass intended access restrictions, as demonstrated using Flash.

oracle-oval
почти 13 лет назад

ELSA-2012-1459: nspluginwrapper security and bug fix update (LOW)

EPSS

Процентиль: 75%
0.00919
Низкий

2.6 Low

CVSS2