7.5
CVE-2012-0960
- EPSS 3.49%
- Veröffentlicht 24.11.2012 20:55:01
- Zuletzt bearbeitet 16.06.2026 23:38:35
- Erkennungen
Unity integration extension (unity-firefox-extension) before 2.4.1 for Firefox does not properly handle callbacks, which allows remote attackers to cause a denial of service (Firefox crash) and possibly execute arbitrary code via a crafted request.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ps Project Management Team ≫ Unity-firefox-extension Update - SwPlatform firefox Version <= 2.4.0
Ps Project Management Team ≫ Unity-firefox-extension Version 0.02 Update - SwPlatform firefox
Ps Project Management Team ≫ Unity-firefox-extension Version 0.2.1 Update - SwPlatform firefox
Ps Project Management Team ≫ Unity-firefox-extension Version 0.3 Update - SwPlatform firefox
Ps Project Management Team ≫ Unity-firefox-extension Version 0.3.1 Update - SwPlatform firefox
Ps Project Management Team ≫ Unity-firefox-extension Version 2.1 Update - SwPlatform firefox
Ps Project Management Team ≫ Unity-firefox-extension Version 2.2 Update - SwPlatform firefox
Ps Project Management Team ≫ Unity-firefox-extension Version 2.3 Update - SwPlatform firefox
Ps Project Management Team ≫ Unity-firefox-extension Version 2.3.1 Update - SwPlatform firefox
Ps Project Management Team ≫ Unity-firefox-extension Version 2.3.2 Update - SwPlatform firefox
Ps Project Management Team ≫ Unity-firefox-extension Version 2.3.3 Update - SwPlatform firefox
Ps Project Management Team ≫ Unity-firefox-extension Version 2.3.4 Update - SwPlatform firefox
Ps Project Management Team ≫ Unity-firefox-extension Version 2.3.5 Update - SwPlatform firefox
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 3.49% | 0.876 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 7.5 | 10 | 6.4 |
AV:N/AC:L/Au:N/C:P/I:P/A:P
|
CWE-20 Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
http://www.securityfocus.com/bid/56650
http://www.ubuntu.com/usn/USN-1639-1
https://bugs.launchpad.net/unity-firefox-extension/%2Bbug/1076350
https://exchange.xforce.ibmcloud.com/vulnerabilities/80319