7.5
CVE-2012-0960
- EPSS 2.31%
- Veröffentlicht 24.11.2012 20:55:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
- Quelle security@ubuntu.com
- CVE-Watchlists
- Unerledigt
Unity integration extension (unity-firefox-extension) before 2.4.1 for Firefox does not properly handle callbacks, which allows remote attackers to cause a denial of service (Firefox crash) and possibly execute arbitrary code via a crafted request.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ps Project Management Team ≫ Unity-firefox-extension Update- SwPlatformfirefox Version <= 2.4.0
Ps Project Management Team ≫ Unity-firefox-extension Version0.02 Update- SwPlatformfirefox
Ps Project Management Team ≫ Unity-firefox-extension Version0.2.1 Update- SwPlatformfirefox
Ps Project Management Team ≫ Unity-firefox-extension Version0.3 Update- SwPlatformfirefox
Ps Project Management Team ≫ Unity-firefox-extension Version0.3.1 Update- SwPlatformfirefox
Ps Project Management Team ≫ Unity-firefox-extension Version2.1 Update- SwPlatformfirefox
Ps Project Management Team ≫ Unity-firefox-extension Version2.2 Update- SwPlatformfirefox
Ps Project Management Team ≫ Unity-firefox-extension Version2.3 Update- SwPlatformfirefox
Ps Project Management Team ≫ Unity-firefox-extension Version2.3.1 Update- SwPlatformfirefox
Ps Project Management Team ≫ Unity-firefox-extension Version2.3.2 Update- SwPlatformfirefox
Ps Project Management Team ≫ Unity-firefox-extension Version2.3.3 Update- SwPlatformfirefox
Ps Project Management Team ≫ Unity-firefox-extension Version2.3.4 Update- SwPlatformfirefox
Ps Project Management Team ≫ Unity-firefox-extension Version2.3.5 Update- SwPlatformfirefox
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 2.31% | 0.833 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.5 | 10 | 6.4 |
AV:N/AC:L/Au:N/C:P/I:P/A:P
|
CWE-20 Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.