Логотип exploitDog
bind:CVE-2012-0455
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2012-0455

Количество 7

Количество 7

ubuntu логотип

CVE-2012-0455

больше 13 лет назад

Mozilla Firefox before 3.6.28 and 4.x through 10.0, Firefox ESR 10.x before 10.0.3, Thunderbird before 3.1.20 and 5.0 through 10.0, Thunderbird ESR 10.x before 10.0.3, and SeaMonkey before 2.8 do not properly restrict drag-and-drop operations on javascript: URLs, which allows user-assisted remote attackers to conduct cross-site scripting (XSS) attacks via a crafted web page, related to a "DragAndDropJacking" issue.

CVSS2: 4.3
EPSS: Низкий
redhat логотип

CVE-2012-0455

больше 13 лет назад

Mozilla Firefox before 3.6.28 and 4.x through 10.0, Firefox ESR 10.x before 10.0.3, Thunderbird before 3.1.20 and 5.0 through 10.0, Thunderbird ESR 10.x before 10.0.3, and SeaMonkey before 2.8 do not properly restrict drag-and-drop operations on javascript: URLs, which allows user-assisted remote attackers to conduct cross-site scripting (XSS) attacks via a crafted web page, related to a "DragAndDropJacking" issue.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2012-0455

больше 13 лет назад

Mozilla Firefox before 3.6.28 and 4.x through 10.0, Firefox ESR 10.x before 10.0.3, Thunderbird before 3.1.20 and 5.0 through 10.0, Thunderbird ESR 10.x before 10.0.3, and SeaMonkey before 2.8 do not properly restrict drag-and-drop operations on javascript: URLs, which allows user-assisted remote attackers to conduct cross-site scripting (XSS) attacks via a crafted web page, related to a "DragAndDropJacking" issue.

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2012-0455

больше 13 лет назад

Mozilla Firefox before 3.6.28 and 4.x through 10.0, Firefox ESR 10.x b ...

CVSS2: 4.3
EPSS: Низкий
github логотип

GHSA-v6mh-5q54-hvfp

больше 3 лет назад

Mozilla Firefox before 3.6.28 and 4.x through 10.0, Firefox ESR 10.x before 10.0.3, Thunderbird before 3.1.20 and 5.0 through 10.0, Thunderbird ESR 10.x before 10.0.3, and SeaMonkey before 2.8 do not properly restrict drag-and-drop operations on javascript: URLs, which allows user-assisted remote attackers to conduct cross-site scripting (XSS) attacks via a crafted web page, related to a "DragAndDropJacking" issue.

EPSS: Низкий
oracle-oval логотип

ELSA-2012-0388

больше 13 лет назад

ELSA-2012-0388: thunderbird security update (CRITICAL)

EPSS: Низкий
oracle-oval логотип

ELSA-2012-0387

больше 13 лет назад

ELSA-2012-0387: firefox security and bug fix update (CRITICAL)

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2012-0455

Mozilla Firefox before 3.6.28 and 4.x through 10.0, Firefox ESR 10.x before 10.0.3, Thunderbird before 3.1.20 and 5.0 through 10.0, Thunderbird ESR 10.x before 10.0.3, and SeaMonkey before 2.8 do not properly restrict drag-and-drop operations on javascript: URLs, which allows user-assisted remote attackers to conduct cross-site scripting (XSS) attacks via a crafted web page, related to a "DragAndDropJacking" issue.

CVSS2: 4.3
1%
Низкий
больше 13 лет назад
redhat логотип
CVE-2012-0455

Mozilla Firefox before 3.6.28 and 4.x through 10.0, Firefox ESR 10.x before 10.0.3, Thunderbird before 3.1.20 and 5.0 through 10.0, Thunderbird ESR 10.x before 10.0.3, and SeaMonkey before 2.8 do not properly restrict drag-and-drop operations on javascript: URLs, which allows user-assisted remote attackers to conduct cross-site scripting (XSS) attacks via a crafted web page, related to a "DragAndDropJacking" issue.

CVSS2: 4.3
1%
Низкий
больше 13 лет назад
nvd логотип
CVE-2012-0455

Mozilla Firefox before 3.6.28 and 4.x through 10.0, Firefox ESR 10.x before 10.0.3, Thunderbird before 3.1.20 and 5.0 through 10.0, Thunderbird ESR 10.x before 10.0.3, and SeaMonkey before 2.8 do not properly restrict drag-and-drop operations on javascript: URLs, which allows user-assisted remote attackers to conduct cross-site scripting (XSS) attacks via a crafted web page, related to a "DragAndDropJacking" issue.

CVSS2: 4.3
1%
Низкий
больше 13 лет назад
debian логотип
CVE-2012-0455

Mozilla Firefox before 3.6.28 and 4.x through 10.0, Firefox ESR 10.x b ...

CVSS2: 4.3
1%
Низкий
больше 13 лет назад
github логотип
GHSA-v6mh-5q54-hvfp

Mozilla Firefox before 3.6.28 and 4.x through 10.0, Firefox ESR 10.x before 10.0.3, Thunderbird before 3.1.20 and 5.0 through 10.0, Thunderbird ESR 10.x before 10.0.3, and SeaMonkey before 2.8 do not properly restrict drag-and-drop operations on javascript: URLs, which allows user-assisted remote attackers to conduct cross-site scripting (XSS) attacks via a crafted web page, related to a "DragAndDropJacking" issue.

1%
Низкий
больше 3 лет назад
oracle-oval логотип
ELSA-2012-0388

ELSA-2012-0388: thunderbird security update (CRITICAL)

больше 13 лет назад
oracle-oval логотип
ELSA-2012-0387

ELSA-2012-0387: firefox security and bug fix update (CRITICAL)

больше 13 лет назад

Уязвимостей на страницу