Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2012-0475

Опубликовано: 25 апр. 2012
Источник: ubuntu
Приоритет: low
EPSS Низкий
CVSS2: 2.6

Описание

Mozilla Firefox 4.x through 11.0, Thunderbird 5.0 through 11.0, and SeaMonkey before 2.9 do not properly construct the Origin and Sec-WebSocket-Origin HTTP headers, which might allow remote attackers to bypass an IPv6 literal ACL via a cross-site (1) XMLHttpRequest or (2) WebSocket operation involving a nonstandard port number and an IPv6 address that contains certain zero fields.

РелизСтатусПримечание
devel

not-affected

12.0+build1-0ubuntu0.12.04.1
hardy

ignored

end of life
lucid

released

12.0+build1-0ubuntu0.10.04.1
natty

released

12.0+build1-0ubuntu0.11.04.1
oneiric

released

12.0+build1-0ubuntu0.11.10.1
precise

released

12.0+build1-0ubuntu0.12.04.1
quantal

not-affected

12.0+build1-0ubuntu0.12.04.1
raring

not-affected

12.0+build1-0ubuntu0.12.04.1
saucy

not-affected

12.0+build1-0ubuntu0.12.04.1
upstream

needs-triage

Показывать по

РелизСтатусПримечание
devel

DNE

hardy

ignored

end of life
lucid

ignored

end of life
natty

ignored

end of life
oneiric

ignored

end of life
precise

DNE

quantal

DNE

raring

DNE

saucy

DNE

upstream

needs-triage

Показывать по

РелизСтатусПримечание
devel

not-affected

15.0+build1-0ubuntu1
hardy

ignored

end of life
lucid

released

12.0.1+build1-0ubuntu0.10.04.1
natty

released

12.0.1+build1-0ubuntu0.11.04.1
oneiric

released

12.0.1+build1-0ubuntu0.11.10.1
precise

released

12.0.1+build1-0ubuntu0.12.04.1
quantal

not-affected

15.0+build1-0ubuntu1
raring

not-affected

15.0+build1-0ubuntu1
saucy

not-affected

15.0+build1-0ubuntu1
upstream

released

12.0.1

Показывать по

РелизСтатусПримечание
devel

DNE

hardy

ignored

end of life
lucid

ignored

end of life
natty

ignored

end of life
oneiric

DNE

precise

DNE

quantal

DNE

raring

DNE

saucy

DNE

upstream

needs-triage

Показывать по

РелизСтатусПримечание
devel

DNE

hardy

DNE

lucid

DNE

natty

ignored

end of life
oneiric

DNE

precise

DNE

quantal

DNE

raring

DNE

saucy

DNE

upstream

needs-triage

Показывать по

EPSS

Процентиль: 52%
0.00289
Низкий

2.6 Low

CVSS2

Связанные уязвимости

redhat
почти 14 лет назад

Mozilla Firefox 4.x through 11.0, Thunderbird 5.0 through 11.0, and SeaMonkey before 2.9 do not properly construct the Origin and Sec-WebSocket-Origin HTTP headers, which might allow remote attackers to bypass an IPv6 literal ACL via a cross-site (1) XMLHttpRequest or (2) WebSocket operation involving a nonstandard port number and an IPv6 address that contains certain zero fields.

nvd
почти 14 лет назад

Mozilla Firefox 4.x through 11.0, Thunderbird 5.0 through 11.0, and SeaMonkey before 2.9 do not properly construct the Origin and Sec-WebSocket-Origin HTTP headers, which might allow remote attackers to bypass an IPv6 literal ACL via a cross-site (1) XMLHttpRequest or (2) WebSocket operation involving a nonstandard port number and an IPv6 address that contains certain zero fields.

debian
почти 14 лет назад

Mozilla Firefox 4.x through 11.0, Thunderbird 5.0 through 11.0, and Se ...

github
почти 4 года назад

Mozilla Firefox 4.x through 11.0, Thunderbird 5.0 through 11.0, and SeaMonkey before 2.9 do not properly construct the Origin and Sec-WebSocket-Origin HTTP headers, which might allow remote attackers to bypass an IPv6 literal ACL via a cross-site (1) XMLHttpRequest or (2) WebSocket operation involving a nonstandard port number and an IPv6 address that contains certain zero fields.

EPSS

Процентиль: 52%
0.00289
Низкий

2.6 Low

CVSS2