Описание
Mozilla Firefox before 15.0, Thunderbird before 15.0, and SeaMonkey before 2.12 do not prevent use of the Object.defineProperty method to shadow the location object (aka window.location), which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via vectors involving a plugin.
Релиз | Статус | Примечание |
---|---|---|
devel | released | 15.0+build1-0ubuntu1 |
hardy | ignored | end of life |
lucid | released | 15.0+build1-0ubuntu0.10.04.1 |
natty | released | 15.0+build1-0ubuntu0.11.04.2 |
oneiric | released | 15.0+build1-0ubuntu0.11.10.1 |
precise | released | 15.0+build1-0ubuntu0.12.04.1 |
quantal | released | 15.0+build1-0ubuntu1 |
raring | released | 15.0+build1-0ubuntu1 |
saucy | released | 15.0+build1-0ubuntu1 |
upstream | released | 15.0 |
Показывать по
Релиз | Статус | Примечание |
---|---|---|
devel | DNE | |
hardy | ignored | end of life |
lucid | ignored | end of life |
natty | ignored | end of life |
oneiric | ignored | end of life |
precise | DNE | |
quantal | DNE | |
raring | DNE | |
saucy | DNE | |
upstream | needs-triage |
Показывать по
Релиз | Статус | Примечание |
---|---|---|
devel | released | 15.0+build1-0ubuntu1 |
hardy | ignored | end of life |
lucid | released | 15.0+build1-0ubuntu0.10.04.1 |
natty | released | 15.0+build1-0ubuntu0.11.04.1 |
oneiric | released | 15.0+build1-0ubuntu0.11.10.1 |
precise | released | 15.0+build1-0ubuntu0.12.04.1 |
quantal | released | 15.0+build1-0ubuntu1 |
raring | released | 15.0+build1-0ubuntu1 |
saucy | released | 15.0+build1-0ubuntu1 |
upstream | released | 15.0 |
Показывать по
Релиз | Статус | Примечание |
---|---|---|
devel | DNE | |
hardy | ignored | end of life |
lucid | ignored | end of life |
natty | ignored | end of life |
oneiric | DNE | |
precise | DNE | |
quantal | DNE | |
raring | DNE | |
saucy | DNE | |
upstream | needs-triage |
Показывать по
Релиз | Статус | Примечание |
---|---|---|
devel | DNE | |
hardy | DNE | |
lucid | DNE | |
natty | ignored | end of life |
oneiric | DNE | |
precise | DNE | |
quantal | DNE | |
raring | DNE | |
saucy | DNE | |
upstream | needs-triage |
Показывать по
EPSS
4.3 Medium
CVSS2
Связанные уязвимости
Mozilla Firefox before 15.0, Thunderbird before 15.0, and SeaMonkey before 2.12 do not prevent use of the Object.defineProperty method to shadow the location object (aka window.location), which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via vectors involving a plugin.
Mozilla Firefox before 15.0, Thunderbird before 15.0, and SeaMonkey before 2.12 do not prevent use of the Object.defineProperty method to shadow the location object (aka window.location), which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via vectors involving a plugin.
Mozilla Firefox before 15.0, Thunderbird before 15.0, and SeaMonkey be ...
Mozilla Firefox before 15.0, Thunderbird before 15.0, and SeaMonkey before 2.12 do not prevent use of the Object.defineProperty method to shadow the location object (aka window.location), which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via vectors involving a plugin.
EPSS
4.3 Medium
CVSS2