Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2013-1711

Опубликовано: 07 авг. 2013
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 4.3

Описание

The XrayWrapper implementation in Mozilla Firefox before 23.0 and SeaMonkey before 2.20 does not properly address the possibility of an XBL scope bypass resulting from non-native arguments in XBL function calls, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks by leveraging access to an unprivileged object.

РелизСтатусПримечание
devel

released

23.0+build2-0ubuntu1
lucid

ignored

end of life
precise

released

23.0+build2-0ubuntu0.12.04.1
quantal

released

23.0+build2-0ubuntu0.12.10.1
raring

released

23.0+build2-0ubuntu0.13.04.1
upstream

released

23.0

Показывать по

EPSS

Процентиль: 80%
0.02158
Низкий

4.3 Medium

CVSS2

Связанные уязвимости

redhat
около 13 лет назад

The XrayWrapper implementation in Mozilla Firefox before 23.0 and SeaMonkey before 2.20 does not properly address the possibility of an XBL scope bypass resulting from non-native arguments in XBL function calls, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks by leveraging access to an unprivileged object.

nvd
около 13 лет назад

The XrayWrapper implementation in Mozilla Firefox before 23.0 and SeaMonkey before 2.20 does not properly address the possibility of an XBL scope bypass resulting from non-native arguments in XBL function calls, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks by leveraging access to an unprivileged object.

debian
около 13 лет назад

The XrayWrapper implementation in Mozilla Firefox before 23.0 and SeaM ...

github
около 4 лет назад

The XrayWrapper implementation in Mozilla Firefox before 23.0 and SeaMonkey before 2.20 does not properly address the possibility of an XBL scope bypass resulting from non-native arguments in XBL function calls, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks by leveraging access to an unprivileged object.

EPSS

Процентиль: 80%
0.02158
Низкий

4.3 Medium

CVSS2

Уязвимость CVE-2013-1711