5
CVE-2011-2486
- EPSS 2.47%
- Veröffentlicht 19.11.2012 12:10:48
- Zuletzt bearbeitet 16.06.2026 23:31:26
- Quelle secalert@redhat.com
- CVE-Watchlists
- Unerledigt
nspluginwrapper before 1.4.4 does not properly provide access to NPNVprivateModeBool variable settings, which could prevent Firefox plugins from determining if they should run in Private Browsing mode and allow remote attackers to bypass intended access restrictions, as demonstrated using Flash.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Nspluginwrapper ≫ Nspluginwrapper Version1.4.2
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 2.47% | 0.824 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 5 | 10 | 2.9 |
AV:N/AC:L/Au:N/C:N/I:P/A:N
|
http://lwn.net/Alerts/524725/
http://rhn.redhat.com/errata/RHSA-2012-1459.html
http://www.securitytracker.com/id?1027757
https://bugzilla.novell.com/show_bug.cgi?id=702034
https://bugzilla.redhat.com/show_bug.cgi?id=715384
https://github.com/davidben/nspluginwrapper/commit/7e4ab8e1189846041f955e6c83f72bc1624e7a98