Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2011-0059

Опубликовано: 02 мар. 2011
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 6.8

Описание

Cross-site request forgery (CSRF) vulnerability in Mozilla Firefox before 3.5.17 and 3.6.x before 3.6.14, and SeaMonkey before 2.0.12, allows remote attackers to hijack the authentication of arbitrary users for requests that were initiated by a plugin and received a 307 redirect to a page on a different web site.

РелизСтатусПримечание
dapper

ignored

end of life
devel

not-affected

4.0~b12+build1+nobinonly-0ubuntu3
hardy

ignored

end of life
karmic

DNE

lucid

released

3.6.14+build3+nobinonly-0ubuntu0.10.04.1
maverick

released

3.6.14+build3+nobinonly-0ubuntu0.10.10.1
natty

not-affected

4.0~b12+build1+nobinonly-0ubuntu3
oneiric

not-affected

4.0~b12+build1+nobinonly-0ubuntu3
precise

not-affected

4.0~b12+build1+nobinonly-0ubuntu3
quantal

not-affected

4.0~b12+build1+nobinonly-0ubuntu3

Показывать по

РелизСтатусПримечание
dapper

DNE

devel

DNE

hardy

released

3.6.14+build3+nobinonly-0ubuntu0.8.04.1
karmic

DNE

lucid

DNE

maverick

DNE

natty

DNE

oneiric

DNE

precise

DNE

quantal

DNE

Показывать по

РелизСтатусПримечание
dapper

DNE

devel

DNE

hardy

DNE

karmic

released

3.6.14+build3+nobinonly-0ubuntu0.9.10.1
lucid

DNE

maverick

DNE

natty

DNE

oneiric

DNE

precise

DNE

quantal

DNE

Показывать по

РелизСтатусПримечание
dapper

DNE

devel

DNE

hardy

ignored

end of life
karmic

ignored

end of life
lucid

ignored

end of life
maverick

ignored

end of life
natty

not-affected

2.0.13+nobinonly-0ubuntu1
oneiric

not-affected

2.0.13+nobinonly-0ubuntu1
precise

DNE

quantal

DNE

Показывать по

РелизСтатусПримечание
dapper

DNE

devel

DNE

hardy

released

1.9.2.14+build3+nobinonly-0ubuntu0.8.04.1
karmic

released

1.9.2.14+build3+nobinonly-0ubuntu0.9.10.1
lucid

released

1.9.2.14+build3+nobinonly-0ubuntu0.10.04.1
maverick

released

1.9.2.14+build3+nobinonly-0ubuntu0.10.10.1
natty

not-affected

1.9.2.14+build3+nobinonly-0ubuntu1
oneiric

DNE

precise

DNE

quantal

DNE

Показывать по

EPSS

Процентиль: 50%
0.00263
Низкий

6.8 Medium

CVSS2

Связанные уязвимости

redhat
больше 14 лет назад

Cross-site request forgery (CSRF) vulnerability in Mozilla Firefox before 3.5.17 and 3.6.x before 3.6.14, and SeaMonkey before 2.0.12, allows remote attackers to hijack the authentication of arbitrary users for requests that were initiated by a plugin and received a 307 redirect to a page on a different web site.

nvd
больше 14 лет назад

Cross-site request forgery (CSRF) vulnerability in Mozilla Firefox before 3.5.17 and 3.6.x before 3.6.14, and SeaMonkey before 2.0.12, allows remote attackers to hijack the authentication of arbitrary users for requests that were initiated by a plugin and received a 307 redirect to a page on a different web site.

debian
больше 14 лет назад

Cross-site request forgery (CSRF) vulnerability in Mozilla Firefox bef ...

github
около 3 лет назад

Cross-site request forgery (CSRF) vulnerability in Mozilla Firefox before 3.5.17 and 3.6.x before 3.6.14, and SeaMonkey before 2.0.12, allows remote attackers to hijack the authentication of arbitrary users for requests that were initiated by a plugin and received a 307 redirect to a page on a different web site.

oracle-oval
больше 14 лет назад

ELSA-2011-0310: firefox security and bug fix update (CRITICAL)

EPSS

Процентиль: 50%
0.00263
Низкий

6.8 Medium

CVSS2

Уязвимость CVE-2011-0059