Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2012-1966

Опубликовано: 17 июл. 2012
Источник: redhat
CVSS2: 4.3
EPSS Низкий

Описание

Mozilla Firefox 4.x through 13.0 and Firefox ESR 10.x before 10.0.6 do not have the same context-menu restrictions for data: URLs as for javascript: URLs, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a crafted URL.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5thunderbirdNot affected
Red Hat Enterprise Linux 6thunderbirdNot affected
Red Hat Enterprise Linux 5firefoxFixedRHSA-2012:108817.07.2012
Red Hat Enterprise Linux 5xulrunnerFixedRHSA-2012:108817.07.2012
Red Hat Enterprise Linux 6firefoxFixedRHSA-2012:108817.07.2012
Red Hat Enterprise Linux 6xulrunnerFixedRHSA-2012:108817.07.2012

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-79
https://bugzilla.redhat.com/show_bug.cgi?id=840207Mozilla: XSS and code execution through data: URLs (MFSA 2012-46)

EPSS

Процентиль: 79%
0.01351
Низкий

4.3 Medium

CVSS2

Связанные уязвимости

ubuntu
около 13 лет назад

Mozilla Firefox 4.x through 13.0 and Firefox ESR 10.x before 10.0.6 do not have the same context-menu restrictions for data: URLs as for javascript: URLs, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a crafted URL.

nvd
около 13 лет назад

Mozilla Firefox 4.x through 13.0 and Firefox ESR 10.x before 10.0.6 do not have the same context-menu restrictions for data: URLs as for javascript: URLs, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a crafted URL.

debian
около 13 лет назад

Mozilla Firefox 4.x through 13.0 and Firefox ESR 10.x before 10.0.6 do ...

github
больше 3 лет назад

Mozilla Firefox 4.x through 13.0 and Firefox ESR 10.x before 10.0.6 do not have the same context-menu restrictions for data: URLs as for javascript: URLs, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a crafted URL.

oracle-oval
около 13 лет назад

ELSA-2012-1088: firefox security update (CRITICAL)

EPSS

Процентиль: 79%
0.01351
Низкий

4.3 Medium

CVSS2