Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2012-1965

Опубликовано: 17 июл. 2012
Источник: redhat
CVSS2: 4.3

Описание

Mozilla Firefox 4.x through 13.0 and Firefox ESR 10.x before 10.0.6 do not properly establish the security context of a feed: URL, which allows remote attackers to bypass unspecified cross-site scripting (XSS) protection mechanisms via a feed:javascript: URL.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5thunderbirdNot affected
Red Hat Enterprise Linux 6thunderbirdNot affected
Red Hat Enterprise Linux 5firefoxFixedRHSA-2012:108817.07.2012
Red Hat Enterprise Linux 5xulrunnerFixedRHSA-2012:108817.07.2012
Red Hat Enterprise Linux 6firefoxFixedRHSA-2012:108817.07.2012
Red Hat Enterprise Linux 6xulrunnerFixedRHSA-2012:108817.07.2012

Показывать по

Дополнительная информация

Статус:

Moderate
https://bugzilla.redhat.com/show_bug.cgi?id=840225Mozilla: feed: URLs with an innerURI inherit security context of page (MFSA 2012-55)

4.3 Medium

CVSS2

Связанные уязвимости

ubuntu
около 13 лет назад

Mozilla Firefox 4.x through 13.0 and Firefox ESR 10.x before 10.0.6 do not properly establish the security context of a feed: URL, which allows remote attackers to bypass unspecified cross-site scripting (XSS) protection mechanisms via a feed:javascript: URL.

nvd
около 13 лет назад

Mozilla Firefox 4.x through 13.0 and Firefox ESR 10.x before 10.0.6 do not properly establish the security context of a feed: URL, which allows remote attackers to bypass unspecified cross-site scripting (XSS) protection mechanisms via a feed:javascript: URL.

debian
около 13 лет назад

Mozilla Firefox 4.x through 13.0 and Firefox ESR 10.x before 10.0.6 do ...

github
больше 3 лет назад

Mozilla Firefox 4.x through 13.0 and Firefox ESR 10.x before 10.0.6 do not properly establish the security context of a feed: URL, which allows remote attackers to bypass unspecified cross-site scripting (XSS) protection mechanisms via a feed:javascript: URL.

oracle-oval
около 13 лет назад

ELSA-2012-1088: firefox security update (CRITICAL)

4.3 Medium

CVSS2