Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2012-5851

Опубликовано: 15 нояб. 2012
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 4.3

Описание

html/parser/XSSAuditor.cpp in WebCore in WebKit, as used in Google Chrome through 22 and Safari 5.1.7, does not consider all possible output contexts of reflected data, which makes it easier for remote attackers to bypass a cross-site scripting (XSS) protection mechanism via a crafted string, aka rdar problem 12019108.

РелизСтатусПримечание
devel

ignored

no update available
esm-apps/xenial

ignored

no update available
esm-infra-legacy/trusty

DNE

trusty/esm was DNE [trusty was ignored [no update available]]
hardy

DNE

lucid

DNE

oneiric

ignored

end of life
precise

ignored

end of life
quantal

ignored

end of life
raring

ignored

end of life
saucy

ignored

end of life

Показывать по

РелизСтатусПримечание
devel

DNE

esm-infra-legacy/trusty

DNE

hardy

ignored

end of life
lucid

ignored

end of life
oneiric

ignored

end of life
precise

ignored

end of life
quantal

ignored

end of life
raring

ignored

end of life
saucy

ignored

end of life
trusty

DNE

Показывать по

РелизСтатусПримечание
devel

not-affected

2.4.9-2ubuntu2
esm-apps/xenial

not-affected

2.4.9-2ubuntu2
esm-infra-legacy/trusty

DNE

trusty/esm was DNE [trusty was not-affected [2.4.8-1ubuntu1~ubuntu14.04.1]]
lucid

DNE

precise

DNE

quantal

DNE

saucy

DNE

trusty

not-affected

2.4.8-1ubuntu1~ubuntu14.04.1
trusty/esm

DNE

trusty was not-affected [2.4.8-1ubuntu1~ubuntu14.04.1]
upstream

needs-triage

Показывать по

EPSS

Процентиль: 56%
0.00344
Низкий

4.3 Medium

CVSS2

Связанные уязвимости

nvd
около 13 лет назад

html/parser/XSSAuditor.cpp in WebCore in WebKit, as used in Google Chrome through 22 and Safari 5.1.7, does not consider all possible output contexts of reflected data, which makes it easier for remote attackers to bypass a cross-site scripting (XSS) protection mechanism via a crafted string, aka rdar problem 12019108.

debian
около 13 лет назад

html/parser/XSSAuditor.cpp in WebCore in WebKit, as used in Google Chr ...

github
больше 3 лет назад

html/parser/XSSAuditor.cpp in WebCore in WebKit, as used in Google Chrome through 22 and Safari 5.1.7, does not consider all possible output contexts of reflected data, which makes it easier for remote attackers to bypass a cross-site scripting (XSS) protection mechanism via a crafted string, aka rdar problem 12019108.

EPSS

Процентиль: 56%
0.00344
Низкий

4.3 Medium

CVSS2