Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2012-0958

Опубликовано: 26 дек. 2012
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 4.3

Описание

content/unity-api.js in the unity-firefox-extension extension 2.4.1 for Firefox exposes the toDataURL function in an API call, which allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via a crafted webpage.

РелизСтатусПримечание
devel

released

2.4.2-0ubuntu1
hardy

DNE

lucid

DNE

oneiric

DNE

precise

DNE

quantal

released

2.4.1-0ubuntu1.2
upstream

needs-triage

Показывать по

EPSS

Процентиль: 55%
0.00319
Низкий

4.3 Medium

CVSS2

Связанные уязвимости

nvd
около 13 лет назад

content/unity-api.js in the unity-firefox-extension extension 2.4.1 for Firefox exposes the toDataURL function in an API call, which allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via a crafted webpage.

github
больше 3 лет назад

content/unity-api.js in the unity-firefox-extension extension 2.4.1 for Firefox exposes the toDataURL function in an API call, which allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via a crafted webpage.

EPSS

Процентиль: 55%
0.00319
Низкий

4.3 Medium

CVSS2