Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2013-5593

Опубликовано: 30 окт. 2013
Источник: ubuntu
Приоритет: low
CVSS2: 4.3

Описание

The SELECT element implementation in Mozilla Firefox before 25.0, Firefox ESR 24.x before 24.1, Thunderbird before 24.1, and SeaMonkey before 2.22 does not properly restrict the nature or placement of HTML within a dropdown menu, which allows remote attackers to spoof the address bar or conduct clickjacking attacks via vectors that trigger navigation off of a page containing this element.

РелизСтатусПримечание
devel

released

25.0+build3-0ubuntu0.13.10.1
lucid

ignored

end of life
precise

released

25.0+build3-0ubuntu0.12.04.1
quantal

released

25.0+build3-0ubuntu0.12.10.1
raring

released

25.0+build3-0ubuntu0.13.04.1
saucy

released

25.0+build3-0ubuntu0.13.10.1
upstream

released

25.0

Показывать по

РелизСтатусПримечание
devel

released

1:24.1.1+build1-0ubuntu0.13.10.1
lucid

ignored

end of life
precise

released

1:24.1.0+build1-0ubuntu0.12.04.1
quantal

released

1:24.1.0+build1-0ubuntu0.12.10.1
raring

released

1:24.1.0+build1-0ubuntu0.13.04.1
saucy

released

1:24.1.0+build1-0ubuntu0.13.10.1
upstream

released

24.1.0

Показывать по

4.3 Medium

CVSS2

Связанные уязвимости

redhat
больше 12 лет назад

The SELECT element implementation in Mozilla Firefox before 25.0, Firefox ESR 24.x before 24.1, Thunderbird before 24.1, and SeaMonkey before 2.22 does not properly restrict the nature or placement of HTML within a dropdown menu, which allows remote attackers to spoof the address bar or conduct clickjacking attacks via vectors that trigger navigation off of a page containing this element.

nvd
больше 12 лет назад

The SELECT element implementation in Mozilla Firefox before 25.0, Firefox ESR 24.x before 24.1, Thunderbird before 24.1, and SeaMonkey before 2.22 does not properly restrict the nature or placement of HTML within a dropdown menu, which allows remote attackers to spoof the address bar or conduct clickjacking attacks via vectors that trigger navigation off of a page containing this element.

debian
больше 12 лет назад

The SELECT element implementation in Mozilla Firefox before 25.0, Fire ...

github
больше 3 лет назад

The SELECT element implementation in Mozilla Firefox before 25.0, Firefox ESR 24.x before 24.1, Thunderbird before 24.1, and SeaMonkey before 2.22 does not properly restrict the nature or placement of HTML within a dropdown menu, which allows remote attackers to spoof the address bar or conduct clickjacking attacks via vectors that trigger navigation off of a page containing this element.

4.3 Medium

CVSS2