[Forgot Password]
Login  Register Subscribe

30480

 
 

423868

 
 

252271

 
 

909

 
 

196835

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2011-2486Date: (C)2012-11-19   (M)2023-12-22


nspluginwrapper before 1.4.4 does not properly provide access to NPNVprivateModeBool variable settings, which could prevent Firefox plugins from determining if they should run in Private Browsing mode and allow remote attackers to bypass intended access restrictions, as demonstrated using Flash.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 5.0
Exploit Score: 10.0
Impact Score: 2.9
 
CVSS V2 Metrics:
Access Vector: NETWORK
Access Complexity: LOW
Authentication: NONE
Confidentiality: NONE
Integrity: PARTIAL
Availability: NONE
  
Reference:
SECTRACK-1027757
RHSA-2012:1459
http://lwn.net/Alerts/524725/
https://bugzilla.novell.com/show_bug.cgi?id=702034
https://bugzilla.redhat.com/show_bug.cgi?id=715384
https://github.com/davidben/nspluginwrapper/commit/7e4ab8e1189846041f955e6c83f72bc1624e7a98

CWE    1
CWE-264
OVAL    3
oval:org.secpod.oval:def:500924
oval:org.secpod.oval:def:1503649
oval:org.secpod.oval:def:202492

© SecPod Technologies