Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2012-0958

Опубликовано: 26 дек. 2012
Источник: ubuntu
Приоритет: medium
CVSS2: 4.3

Описание

content/unity-api.js in the unity-firefox-extension extension 2.4.1 for Firefox exposes the toDataURL function in an API call, which allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via a crafted webpage.

РелизСтатусПримечание
devel

released

2.4.2-0ubuntu1
hardy

DNE

lucid

DNE

oneiric

DNE

precise

DNE

quantal

released

2.4.1-0ubuntu1.2
upstream

needs-triage

Показывать по

4.3 Medium

CVSS2

Связанные уязвимости

nvd
больше 13 лет назад

content/unity-api.js in the unity-firefox-extension extension 2.4.1 for Firefox exposes the toDataURL function in an API call, which allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via a crafted webpage.

github
больше 4 лет назад

content/unity-api.js in the unity-firefox-extension extension 2.4.1 for Firefox exposes the toDataURL function in an API call, which allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via a crafted webpage.

4.3 Medium

CVSS2

Уязвимость CVE-2012-0958