Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2013-5593

Опубликовано: 30 окт. 2013
Источник: ubuntu
Приоритет: low
EPSS Низкий
CVSS2: 4.3

Описание

The SELECT element implementation in Mozilla Firefox before 25.0, Firefox ESR 24.x before 24.1, Thunderbird before 24.1, and SeaMonkey before 2.22 does not properly restrict the nature or placement of HTML within a dropdown menu, which allows remote attackers to spoof the address bar or conduct clickjacking attacks via vectors that trigger navigation off of a page containing this element.

РелизСтатусПримечание
devel

released

25.0+build3-0ubuntu0.13.10.1
lucid

ignored

end of life
precise

released

25.0+build3-0ubuntu0.12.04.1
quantal

released

25.0+build3-0ubuntu0.12.10.1
raring

released

25.0+build3-0ubuntu0.13.04.1
saucy

released

25.0+build3-0ubuntu0.13.10.1
upstream

released

25.0

Показывать по

РелизСтатусПримечание
devel

released

1:24.1.1+build1-0ubuntu0.13.10.1
lucid

ignored

end of life
precise

released

1:24.1.0+build1-0ubuntu0.12.04.1
quantal

released

1:24.1.0+build1-0ubuntu0.12.10.1
raring

released

1:24.1.0+build1-0ubuntu0.13.04.1
saucy

released

1:24.1.0+build1-0ubuntu0.13.10.1
upstream

released

24.1.0

Показывать по

EPSS

Процентиль: 79%
0.01993
Низкий

4.3 Medium

CVSS2

Связанные уязвимости

redhat
почти 13 лет назад

The SELECT element implementation in Mozilla Firefox before 25.0, Firefox ESR 24.x before 24.1, Thunderbird before 24.1, and SeaMonkey before 2.22 does not properly restrict the nature or placement of HTML within a dropdown menu, which allows remote attackers to spoof the address bar or conduct clickjacking attacks via vectors that trigger navigation off of a page containing this element.

nvd
почти 13 лет назад

The SELECT element implementation in Mozilla Firefox before 25.0, Firefox ESR 24.x before 24.1, Thunderbird before 24.1, and SeaMonkey before 2.22 does not properly restrict the nature or placement of HTML within a dropdown menu, which allows remote attackers to spoof the address bar or conduct clickjacking attacks via vectors that trigger navigation off of a page containing this element.

debian
почти 13 лет назад

The SELECT element implementation in Mozilla Firefox before 25.0, Fire ...

github
около 4 лет назад

The SELECT element implementation in Mozilla Firefox before 25.0, Firefox ESR 24.x before 24.1, Thunderbird before 24.1, and SeaMonkey before 2.22 does not properly restrict the nature or placement of HTML within a dropdown menu, which allows remote attackers to spoof the address bar or conduct clickjacking attacks via vectors that trigger navigation off of a page containing this element.

EPSS

Процентиль: 79%
0.01993
Низкий

4.3 Medium

CVSS2